Executive brief
Splunk Enterprise is a widely-used data analytics and security information platform. Users without administrative privileges could bypass access controls to create or modify scripted lookups and execute them with the permissions of the Splunk service account, potentially gaining access to all indexed data and compromising system integrity. This affects multiple versions of Splunk Enterprise released between 2024 and 2026.
Technical details
The vulnerability is an authorization bypass (CWE-862) in the generic transforms configuration REST API endpoints. The vulnerable component fails to enforce required "admin" or "power" role capabilities when users create or modify external lookup definitions through configuration endpoints. An unauthenticated or low-privileged user can create a malicious scripted lookup and trigger execution with the privileges of the Splunk Enterprise process owner. This leads to arbitrary code execution in the context of the Splunk service account. Patches are available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14; additional hardening steps are recommended per the advisory.
Affected products
- Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Patches released for versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14