Remote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk Enterprise
Published Mar 11, 2026
8.0
HIGHCVSS 3.1
EPSS 0.46%
Description
In Splunk Enterprise versions below 10.2.0, 10.0.4, 9.4.9, and 9.3.10, and Splunk Cloud Platform versions below 10.2.2510.5, 10.0.2503.12, 10.1.2507.16, and 9.3.2411.124, a user who holds a role that contains the high-privilege capability `edit_cmd` could execute arbitrary shell commands using the `unarchive_cmd` parameter for the `/splunkd/__upload/indexing/preview` REST endpoint.
Affected products
-
- Version 10.0.2503StatusaffectedConstraints<10.0.2503.12
- Version 10.1.2507StatusaffectedConstraints<10.1.2507.16
- Version 10.2.2510StatusaffectedConstraints<10.2.2510.5
- Version 9.3.2411StatusaffectedConstraints<9.3.2411.124
- Version
-
- Version 10.0StatusaffectedConstraints<10.0.4
- Version 9.3StatusaffectedConstraints<9.3.10
- Version 9.4StatusaffectedConstraints<9.4.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Splunk | Splunk Cloud Platform | n/a |
| |||||||||||||||
| Splunk | Splunk Enterprise | n/a |
|
Configuration 1
Configuration 2
- ≥ 9.3.2411 · < 9.3.2411.124
- ≥ 10.0.2503 · < 10.0.2503.12
- ≥ 10.1.2507 · < 10.1.2507.16
- ≥ 10.2.2510 · < 10.2.2510.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
1 other source (NVD) ▾
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Mar 12, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Mar-Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.46% (0.00462) | 37.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.46% (0.00462) | 36.34th | v5 (v2026.06.15) |
| Mar 12, 2026 | 0.05% (0.00047) | 14.18th | v4 (v2025.03.14) |
References (1)
- https://advisory.splunk.com/advisories/SVD-2026-0302 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0302 | Vendor Advisory |
Change history (0)
No recorded changes yet.