Back to Database
Status published
High
CVE-2022-43571
Remote Code Execution through dashboard PDF generation component in Splunk Enterprise
Vulnerability Description
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, an authenticated user can execute arbitrary code through the dashboard PDF generation component.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-43571
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Danylo Dmytriiev (DDV_UA)
References
More from Splunk
View All →CVE-2025-22621
Privilege escalation for users who hold the “splunk_app_soar“ role in the Splunk App for SOAR
Medium
6.4
CVE-2025-20389
Improper Input Validation in "label" column field in Splunk Secure Gateway App
Medium
4.3
CVE-2025-20388
Blind Server Side Request Forgery (SSRF) through Distributed Search Peers in Splunk Enterprise
Low
2.7
CVE-2025-20387
Incorrect permissions assignment on Splunk Universal Forwarder for Windows during new installation or upgrade
High
8
CVE-2025-20386
Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade
High
8
Affected Vendor
Splunk
View all reports →Affected Software
Splunk Enterprise
Vulnerable Versions:
8.1, 8.2, 9.0
Timeline
Official Publish:
November 3rd, 2022
Last Modified:
May 2nd, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H