Splunk documented and later removed a detection for privilege escalation in which low-privilege users could abuse the edit_user capability to obtain administrative access. The analytic monitored _audit logs for password-related actions including change_own_password, password_change, and edit_password when access was granted to accounts that were not administrators or system users, and warned that successful exploitation could result in full control of the Splunk environment and potential data exposure.
The detection was mapped to MITRE ATT&CK technique T1548: Abuse Elevation Control Mechanism, which covers privilege escalation and defense evasion through misuse of built-in control mechanisms across platforms. Splunk marked the analytic as deprecated and removed it after the underlying issue, tracked as CVE-2023-32707, was patched in current releases, noting the detection had been disabled by default, required access to the _audit index, and could produce false positives during legitimate password changes.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the "Splunk Edit User Privilege Escalation" detection from its content library in version 5.6.0 because the associated vulnerabilities had been patched in the latest Splunk release. The detection was designed to identify low-privilege users abusing the edit_user capability and was associated with CVE-2023-32707.
The MITRE ATT&CK technique entry for T1548, Abuse Elevation Control Mechanism, was last modified. The entry covers sub-techniques T1548.001 through T1548.006 and maps them to Privilege Escalation and Defense Evasion across multiple platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.