Executive brief
Splunk Enterprise allows users with the "power" role to store malicious search commands in Table Editor datasets that execute with elevated "admin" permissions when opened by administrators. An attacker would need to trick an admin into opening a specially crafted dataset to succeed. This could lead to unauthorized data access or modification on the search head, compromising the security of the Splunk instance.
Technical details
The vulnerability is a privilege escalation through improper SPL (Search Processing Language) validation in Splunk Enterprise's Table Editor. The root cause is that the Table Editor does not apply SPL safeguards for risky commands when preparing dataset initial data, allowing a "power" role user to inject malicious commands. When an "admin" role user opens the compromised dataset, the unsafe SPL executes with the admin's elevated permissions. Attack vectors include phishing or social engineering to trick the admin into initiating the request within their browser. The attacker can expose sensitive data or modify limited data on the search head. Patches are available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
Affected products
- Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14
Timeline
- 2026-08-19: disclosed