Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-46214

84
FAUCET Score

CVE-2023-46214 is a critical remote code execution vulnerability affecting Splunk Enterprise versions below 9.0.7 and 9.1.2. The flaw stems from insufficient sanitization of user-supplied extensible stylesheet language transformations (XSLT), allowing an attacker to upload malicious XSLT and execute arbitrary code on the Splunk instance. With a CVSS score of 8.8 (High) and an EPSS score indicating high exploitability, this vulnerability presents a significant risk due to its network-based attack vector and high impact on confidentiality, integrity, and availability. While not currently on the CISA KEV catalog or Hot List, a Metasploit module exists for authenticated exploitation, and its FAUCET Risk Score of 99/100 underscores its severity, despite limited public discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 9.1.2308CPE matchmatch criteria
cpe:2.3:a:splunk:cloud:*:*:*:*:*:*:*:*
>= 9.0.0, < 9.0.7CPE matchmatch criteria
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
>= 9.1.0, < 9.1.2CPE matchmatch criteria
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.0HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
89.07%
Probability of exploitation in next 30 days
EPSS Percentile
99.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Splunk Authenticated XSLT Upload RCE · Nov 28, 2023
This CVE's current EPSS score of 0.8907 is in the 100th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

zimbrapatch availablevia llm_extracted
Fixed in: 9.0.7, 9.1.2, 9.1.2308

Vendor Advisories (1)

zimbrallm-zimbra-9ed109e4cf9013f3HIGH

Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing

Nov 16, 2023

References

advisory.splunk.com / advisories/SVD-2023-1104
Vendor Advisory
research.splunk.com / application/6cb7e011-55fb-48e3-a98d-164fa854e37e
Vendor Advisory
research.splunk.com / application/a053e6a6-2146-483a-9798-2d43652f3299
Vendor Advisory