Executive brief
Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching large datasets. A security flaw in the Deployment Server component could allow an attacker to trick an authorized user into unknowingly running malicious searches. If successful, this could allow the attacker to steal stored credentials and access sensitive indexed data, potentially compromising the entire monitoring environment.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in the Deployment Server endpoints of Splunk Web. The root cause is twofold: the application fails to validate CSRF tokens on GET requests and fails to neutralize caller-supplied input before incorporating it into Search Processing Language (SPL) queries. An unauthenticated remote attacker can exploit this by tricking a user with 'list_deployment_server' capabilities into visiting a malicious URL. This results in the execution of arbitrary SPL searches as the high-privileged 'splunk-system-user', enabling unauthorized access to credentials and indexed data. The issue is resolved in Splunk Enterprise versions 10.4.1, 10.2.5, 10.0.8, 9.4.13, and various Splunk Cloud Platform maintenance releases.
Affected products
- Splunk Splunk Enterprise < 10.4.1, < 10.2.5, < 10.0.8, < 9.4.13
- Splunk Splunk Cloud Platform < 10.5.2605.0, < 10.4.2604.7, < 10.3.2512.16, < 10.2.2510.18, < 10.1.2507.24
Timeline
- 2026-07-15: disclosed
- 2026-07-15: advisory
- 2026-07-15: patched