← Vulnerability feed

Vulnerability record · CVE-2023-32707 · published 1 June 2023

CVE-2023-32707: Splunk Enterprise privilege escalation via crafted web requests

Splunk · Splunk

Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below 9.0.2303.100, allow a low-privileged user with the 'edit_user' capability to escalate to admin by sending specially crafted web requests. The flaw is an improper authorization (CWE-285) issue in the user-editing path, and it matters because a routine delegated role becomes a full administrative takeover.

8.8 CVSS 3.1 High EPSS 79% · top 0.4% CWE-285 · Improper authorization
8.8CVSS 3.1 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityA network-reachable, low-privilege-to-admin escalation with CVSS 8.8 and very high EPSS makes this a high-priority fix despite no KEV listing.

What it is

Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below 9.0.2303.100, allow a low-privileged user with the 'edit_user' capability to escalate to admin by sending specially crafted web requests. The flaw is an improper authorization (CWE-285) issue in the user-editing path, and it matters because a routine delegated role becomes a full administrative takeover.

Impact

An attacker with a low-privileged account gains full admin privileges, giving control over Splunk configuration, data, and any connected integrations.

Attack surface

Reached over the network through the Splunk web interface; the attacker needs an authenticated account whose role holds the 'edit_user' capability, and no user interaction is required.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high (0.79, 99.6th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Splunk Enterprise to 9.0.5, 8.2.11, or 8.1.14 (or later) and Splunk Cloud Platform to 9.0.2303.100 or later.
  • Audit roles for the 'edit_user' capability and remove it from any role that does not strictly require it.
  • Restrict web interface access to trusted networks and enforce strong authentication on all Splunk accounts.
  • Review and reduce the number of low-privileged accounts that can reach the Splunk web UI.
  • Monitor Splunk admin audit logs for unexpected privilege or role changes.

Detection

  • Alert on role or capability changes, especially grants of admin or 'edit_user', in Splunk audit logs.
  • Monitor for web requests to user-edit endpoints from accounts that normally do not perform user administration.
  • Baseline and alert on new admin account creation or privilege escalation events in Splunk.
  • Correlate low-privileged account activity with subsequent administrative actions in the same session.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32707 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-20253Splunk Enterprise PostgreSQL sidecar missing authentication allows file writesSplunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any networ…KEVEPSS 97%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2022-32158Splunk improper access control vulnerabilitySplunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients t…EPSS 1.4%9.8CVE-2022-37437Splunk improper certificate validation vulnerabilityWhen using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is …EPSS 0.44%9.8CVE-2017-17067Splunk incorrect authorization vulnerabilitySplunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the…EPSS 3.0%9.8CVE-2016-10126Splunk permissions and access controls vulnerabilitySplunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x bef…EPSS 4.0%9.4CVE-2026-76310Splunk improper access control vulnerabilityIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the a…EPSS 0.45%9.4CVE-2026-76311Splunk improper access control vulnerabilityIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the d…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2023-32707), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.