Impact
In Splunk Enterprise Security versions lower than 8.6.1, a user with the ess_analyst role can modify User and Entity Behavior Analytics search macros that are executed with administrator privileges. This allows the user to run scheduled searches with elevated permissions, granting them access to all relevant data and compromising system integrity. The weakness stems from incorrect access control—write permissions are granted to analyst roles for objects that should be administrator‑only, a classic example of CWE‑732.
Affected Systems
Splunk Enterprise Security, any release prior to 8.6.1. The vulnerability is present in all affected versions regardless of minor build number, as the access control flaw is in the UEBA app metadata rather than a specific sub‑version.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity flaw. Because the EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog, current exploitation evidence is unknown, but the attack vector is inferred to be an authenticated, internal user with the ess_analyst role. Once the analyst gains write access to the macros, they can elevate privileges and read all data, leading to potential data exfiltration, tampering, and full system compromise. The risk is therefore significant for organizations that rely on the default split‑role configuration.
OpenCVE Enrichment