Vulnerability record · CVE-2023-46214 · published 16 November 2023
CVE-2023-46214: Splunk Enterprise unsafe XSLT sanitization enables remote code execution
Splunk · Cloud
Splunk Enterprise below 9.0.7 and 9.1.2 does not safely sanitize user-supplied XSLT. An attacker can upload malicious XSLT that results in remote code execution on the Splunk Enterprise instance. The flaw is an XML injection class issue (CWE-91) with a high CVSS score of 8.8.
Description
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability and high EPSS (0.89174) make this a serious RCE risk, though it requires user interaction and is not in KEV.
What it is
Splunk Enterprise below 9.0.7 and 9.1.2 does not safely sanitize user-supplied XSLT. An attacker can upload malicious XSLT that results in remote code execution on the Splunk Enterprise instance. The flaw is an XML injection class issue (CWE-91) with a high CVSS score of 8.8.
Impact
Successful exploitation gives the attacker remote code execution on the Splunk Enterprise instance, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the Splunk host and any data or credentials it holds.
Attack surface
The vector is network-reachable (AV:N) with no privileges required (PR:N), but exploitation requires user interaction (UI:R), consistent with an attacker needing a user to supply or process the malicious XSLT. No specific affected interface beyond XSLT upload is described in the record.
Exploitation
The CVE is not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.89174 (99.77th percentile), indicating elevated likelihood of exploitation activity. All references are vendor advisories and detection guidance, with no public exploit tag supplied.
What to do
- Upgrade Splunk Enterprise to 9.0.7 or 9.1.2 or later as directed by the vendor advisory SVD-2023-1104.
- Restrict who can upload or supply XSLT content and review existing custom XSLT for untrusted input.
- Apply network controls so the Splunk management and web interfaces are not exposed to untrusted networks.
- Monitor the vendor advisory and detection guidance for any additional hardening steps.
Detection
- Review Splunk audit and web logs for XSLT uploads or processing of untrusted stylesheets.
- Use the vendor-provided detection searches referenced in the Splunk research advisories.
- Alert on unexpected process execution or child processes spawned by the Splunk service account.
- Monitor for anomalous file writes or configuration changes in Splunk app and configuration directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2023-1104 | Vendor Advisory |
| https://research.splunk.com/application/6cb7e011-55fb-48e3-a98d-164fa854e37e/ | Vendor Advisory |
| https://research.splunk.com/application/a053e6a6-2146-483a-9798-2d43652f3299/ | Vendor Advisory |
| https://advisory.splunk.com/advisories/SVD-2023-1104 | Vendor Advisory |
| https://research.splunk.com/application/6cb7e011-55fb-48e3-a98d-164fa854e37e/ | Vendor Advisory |
| https://research.splunk.com/application/a053e6a6-2146-483a-9798-2d43652f3299/ | Vendor Advisory |
Track CVE-2023-46214 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46214), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.