Impact
An authenticated user who holds a role containing the mc_investigation_read capability in Splunk Enterprise Security versions earlier than 8.6.1 can inject arbitrary Search Processing Language (SPL) through the Analyst Queue REST API. The Analyst Queue filter handling fails to validate filter field names before including them in SPL searches, allowing the attacker to execute malicious SPL commands. This flaw can reveal sensitive data and modify scheduled searches, thereby compromising confidentiality, integrity, and availability of the system. The weakness is an input validation failure, classified as CWE-20.
Affected Systems
The vulnerability affects Splunk Enterprise Security deployments running any version older than 8.6.1. Only the Splunk Enterprise Security product is impacted; other Splunk products are not listed as affected.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS scores are not available, and the vulnerability is not in the CISA KEV catalog, so no current evidence of widespread exploitation is documented. Exploitation requires authenticated access to the Splunk Enterprise Security REST API with a role that includes mc_investigation_read, implying an internal attacker or a compromised privileged user. If such a user submits crafted search filter parameters, the attacker can run arbitrary SPL within the context of the scheduled searches, potentially accessing or altering all data accessible to that user.
OpenCVE Enrichment