Impact
A user with the Splunk "power" role can modify scheduled searches provided by the Splunk AI Toolkit in versions below 6.0.1. By changing these scheduled searches, the user can execute arbitrary Search Processing Language (SPL) commands using the permissions of the search owner. This allows the attacker to query all data accessible to the owner, potentially exposing sensitive information and altering system state. The vulnerability is classified under CWE-732, improper access control for privileged functions.
Affected Systems
The vulnerability affects installations of Splunk AI Toolkit that are older than version 6.0.1. Any instance of the app in which the vendor Splunk provides it is affected. Affected versions include all releases prior to 6.0.1.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS is not available, so the probability of exploitation is currently unknown, but the flaw requires a user with the "power" role, which denotes an elevated privilege level. The vulnerability is not listed in CISA KEV. Because the remote attacker must possess a privileged account, the likely attack vector is internal or through any system that assigns the "power" role.
OpenCVE Enrichment