CVE-2023-40598: Splunk
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
In Splunk Enterprise versions below 8.2.12, 9.0.6, and 9.1.1, an attacker can create an external lookup that calls a legacy internal function. The attacker can use this internal function to insert code into the Splunk platform installation directory. From there, a user can execute arbitrary code on the Splunk platform Instance.
Affected products
- Splunk Splunk: before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.6 (fixed in 9.0.6); from 9.1.0, before 9.1.1 (fixed in 9.1.1)
- Splunk Splunk Cloud Platform: before 9.0.2305.200 (fixed in 9.0.2305.200)
Published 2023-08-30. Last modified 2026-06-17.