Impact
The vulnerability arises from insufficient validation of the bundle file names during search head cluster replication, allowing a crafted REST API request to cause the Splunk Enterprise process to delete or temporarily overwrite any writable file on the non‑captain member. This changes critical system files, leading to loss of data and disruption of Splunk services, directly compromising the integrity and availability of the platform. The weakness is classified as a path‑traversal flaw (CWE‑158).
Affected Systems
Affected are Splunk Enterprise deployments running any version older than 10.4.2, 10.2.6, 10.0.9, or 9.4.14 that are configured as non‑captain search head cluster members. A user who does not have the admin or power role can exploit the issue through the REST API.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity, while the EPSS score is not available, making it unclear how often it is expected to be exploited. The vulnerability is not listed in the CISA KEV catalog. An attacker would need network access to the Splunk REST interface and only needs an account with a non‑admin role; the lack of validation of bundle names and NUL byte neutralization is the main exploitation vector. The likely attack vector is through a crafted REST API request from an external user or compromised account.
OpenCVE Enrichment