Executive brief
Splunk Enterprise, a widely-used data analytics and monitoring platform, contains a privilege escalation vulnerability in its scheduled search alert feature. A user with basic scheduling permissions can configure PDF email alerts that execute with system-level privileges, allowing them to run arbitrary commands, expose sensitive data, and potentially compromise the entire search head infrastructure.
Technical details
The vulnerability is a privilege escalation flaw (CWE-269) in how Splunk Enterprise handles authentication context during PDF attachment rendering in email alert actions. When a scheduled search triggers an email alert with PDF attachments, the search scheduler incorrectly passes a system-level authentication context to the alert action instead of the action owner's context. This allows a user holding the schedule_search capability to execute arbitrary SPL (Search Processing Language) commands with elevated privileges. The attack requires the attacker to have schedule_search capability but no administrative role. The vulnerability affects versions before 10.4.2, 10.2.6, 10.0.9, and 9.4.14; patches are available.
Affected products
- Splunk Enterprise before 10.4.2, 10.2.6, 10.0.9, and 9.4.14
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Patches released in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14