Affected Systems
Splunk Enterprise versions below 10.2.4 and 10.0.7. The vulnerability enables unauthenticated attackers to perform arbitrary file operations and achieve remote code execution. CVSS score 9.8 (Critical).
Exploitation Status
No active exploitation or public PoC mentioned in available data. Given the critical CVSS score and unauthenticated attack vector, exploitation likelihood is high once details become public.
Business Impact
Splunk Enterprise is widely deployed for security monitoring and log aggregation in enterprise environments. Successful exploitation grants attackers full system control over Splunk infrastructure, enabling data exfiltration of sensitive logs, persistence mechanisms, and potential lateral movement. Organizations relying on Splunk for security operations face severe risk if instances are internet-facing or accessible from untrusted networks.
Urgency
🔴 Immediate
Recommended Actions
- Immediately upgrade Splunk Enterprise to version 10.2.4 or 10.0.7 (or later) depending on your major version branch
- Audit network exposure of all Splunk Enterprise instances and restrict access to trusted management networks only
- Review Splunk access logs (splunkd_access.log and audit.log) for suspicious unauthenticated requests or unusual file operations prior to patching
- If immediate patching is not feasible, implement strict firewall rules or WAF policies to block unauthenticated access to Splunk web interfaces
- Verify that Splunk instances are not directly exposed to the internet; use VPN or jump hosts for administrative access
