← Back to browse · API

CVE-2023-32707

Severity
HIGH
CVSS
8.8
EPSS
0.78877
Risk score
62.81
CISA KEV
No
PoC
No
Published
2023-06-01
Modified
2025-03-11
First seen
2026-08-07
Aliases
EUVD-2023-36934, GHSA-M653-M4XM-RXRR
Products
Splunk:Splunk Cloud Platform - <9.0.2303.100, Splunk:Splunk Enterprise 8.1 <8.1.14, Splunk:Splunk Enterprise 8.2 <8.2.11, Splunk:Splunk Enterprise 9.0 <9.0.5
Sources
euvd EUVD-2023-36934

Description

In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below version 9.0.2303.100, a low-privileged user who holds a role that has the ‘edit_user’ capability assigned to it can escalate their privileges to that of the admin user by providing specially crafted web requests.

References