← Vulnerability feed

Vulnerability record · CVE-2023-46214 · published 16 November 2023

CVE-2023-46214: Splunk Enterprise unsafe XSLT sanitization enables remote code execution

Splunk · Cloud

Splunk Enterprise below 9.0.7 and 9.1.2 does not safely sanitize user-supplied XSLT. An attacker can upload malicious XSLT that results in remote code execution on the Splunk Enterprise instance. The flaw is an XML injection class issue (CWE-91) with a high CVSS score of 8.8.

8.8 CVSS 3.1 High EPSS 89% · top 0.2% CWE-91 · XML injection
8.8CVSS 3.1 base score
89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability and high EPSS (0.89174) make this a serious RCE risk, though it requires user interaction and is not in KEV.

What it is

Splunk Enterprise below 9.0.7 and 9.1.2 does not safely sanitize user-supplied XSLT. An attacker can upload malicious XSLT that results in remote code execution on the Splunk Enterprise instance. The flaw is an XML injection class issue (CWE-91) with a high CVSS score of 8.8.

Impact

Successful exploitation gives the attacker remote code execution on the Splunk Enterprise instance, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the Splunk host and any data or credentials it holds.

Attack surface

The vector is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), consistent with an attacker needing a user to supply or process the malicious XSLT. No specific affected interface beyond XSLT upload is described in the record.

Exploitation

The CVE is not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.89174 (99.77th percentile), indicating elevated likelihood of exploitation activity. All references are vendor advisories and detection guidance, with no public exploit tag supplied.

What to do

  • Upgrade Splunk Enterprise to 9.0.7 or 9.1.2 or later as directed by the vendor advisory SVD-2023-1104.
  • Restrict who can upload or supply XSLT content and review existing custom XSLT for untrusted input.
  • Apply network controls so the Splunk management and web interfaces are not exposed to untrusted networks.
  • Monitor the vendor advisory and detection guidance for any additional hardening steps.

Detection

  • Review Splunk audit and web logs for XSLT uploads or processing of untrusted stylesheets.
  • Use the vendor-provided detection searches referenced in the Splunk research advisories.
  • Alert on unexpected process execution or child processes spawned by the Splunk service account.
  • Monitor for anomalous file writes or configuration changes in Splunk app and configuration directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-46214 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-20253Splunk Enterprise PostgreSQL sidecar missing authentication allows file writesSplunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any networ…KEVEPSS 97%analysed7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2022-32158Splunk improper access control vulnerabilitySplunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients t…EPSS 1.4%9.8CVE-2022-37437Splunk improper certificate validation vulnerabilityWhen using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is …EPSS 0.44%9.8CVE-2017-17067Splunk incorrect authorization vulnerabilitySplunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the…EPSS 3.0%9.8CVE-2016-10126Splunk permissions and access controls vulnerabilitySplunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x bef…EPSS 4.0%9.4CVE-2026-76310Splunk improper access control vulnerabilityIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the a…EPSS 0.45%9.4CVE-2026-76311Splunk improper access control vulnerabilityIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the d…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2023-46214), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.