Splunk documented and later removed a detection for attempts to abuse a cross-site request forgery vulnerability, tracked as CVE-2024-45737, to change KVStore maintenance mode in Splunk Enterprise and Splunk Cloud Platform. The issue allowed low-privileged users without admin or power roles to alter KVStore state in affected releases, including Splunk Enterprise versions earlier than 9.3.1, 9.2.3, and 9.1.6, and Splunk Cloud Platform versions earlier than 9.2.2403.108, 9.1.2312.204, and 9.1.2308.211.
The activity was mapped to MITRE ATT&CK T1489 Service Stop, a technique commonly used by ransomware and destructive malware to terminate or disable services, security tools, backups, databases, and virtualization processes in order to increase operational impact and hinder recovery. MITRE’s catalog shows the technique is widely used by families including Conti, LockBit, Ryuk, and BlackCat, as well as disruptive malware such as HermeticWiper and KillDisk; Splunk said the related detection was removed from its Threat Research library after the underlying vulnerabilities were patched in current releases.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the detection "Splunk Disable KVStore via CSRF Enabling Maintenance Mode" from its content library in version 5.6.0 because the associated CVEs had been patched in current releases. The detection update date is listed as 2026-05-14.
Splunk patched the CVEs associated with a cross-site request forgery issue that could let a low-privileged user change App Key Value Store maintenance mode. The issue affected multiple Splunk Enterprise and Splunk Cloud Platform versions and is referenced as CVE-2024-45737 and advisory SVD-2024-1007.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.