Vulnerability record · CVE-2023-32707 · published 1 June 2023
CVE-2023-32707: Splunk Enterprise privilege escalation via crafted web requests
Splunk · Splunk
Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below 9.0.2303.100, allow a low-privileged user with the 'edit_user' capability to escalate to admin by sending specially crafted web requests. The flaw is an improper authorization (CWE-285) issue in the user-editing path, and it matters because a routine delegated role becomes a full administrative takeover.
Description
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityA network-reachable, low-privilege-to-admin escalation with CVSS 8.8 and very high EPSS makes this a high-priority fix despite no KEV listing.
What it is
Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below 9.0.2303.100, allow a low-privileged user with the 'edit_user' capability to escalate to admin by sending specially crafted web requests. The flaw is an improper authorization (CWE-285) issue in the user-editing path, and it matters because a routine delegated role becomes a full administrative takeover.
Impact
An attacker with a low-privileged account gains full admin privileges, giving control over Splunk configuration, data, and any connected integrations.
Attack surface
Reached over the network through the Splunk web interface; the attacker needs an authenticated account whose role holds the 'edit_user' capability, and no user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high (0.79, 99.6th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade Splunk Enterprise to 9.0.5, 8.2.11, or 8.1.14 (or later) and Splunk Cloud Platform to 9.0.2303.100 or later.
- Audit roles for the 'edit_user' capability and remove it from any role that does not strictly require it.
- Restrict web interface access to trusted networks and enforce strong authentication on all Splunk accounts.
- Review and reduce the number of low-privileged accounts that can reach the Splunk web UI.
- Monitor Splunk admin audit logs for unexpected privilege or role changes.
Detection
- Alert on role or capability changes, especially grants of admin or 'edit_user', in Splunk audit logs.
- Monitor for web requests to user-edit endpoints from accounts that normally do not perform user administration.
- Baseline and alert on new admin account creation or privilege escalation events in Splunk.
- Correlate low-privileged account activity with subsequent administrative actions in the same session.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2023-0602 | Vendor Advisory |
| https://research.splunk.com/application/39e1c326-67d7-4c0d-8584-8056354f6593/ | Vendor Advisory |
| https://advisory.splunk.com/advisories/SVD-2023-0602 | Vendor Advisory |
| https://research.splunk.com/application/39e1c326-67d7-4c0d-8584-8056354f6593/ | Vendor Advisory |
Track CVE-2023-32707 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.