Splunk disclosed and patched CVE-2024-45734, an image file disclosure vulnerability in Splunk Enterprise that allowed low-privileged users without admin or power roles to view images stored on the host machine through the PDF export feature in classic dashboards. The issue affected versions 9.3.0, 9.2.3, and 9.1.6, creating a path for unauthorized access to locally referenced image content embedded in dashboards using version 1.1 and <img> tags.
Splunk Threat Research had published a detection to help defenders identify possible exploitation by hunting for generated PDFs tied to classic dashboards and looking for indicators such as localhost image paths, but that content was later removed after the flaw was patched in current releases. The exposure aligns with attacker tradecraft described in MITRE ATT&CK T1087 Account Discovery, where adversaries abuse accessible interfaces, built-in tools, or misconfigurations to gather information that can support follow-on compromise and privilege abuse.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk Threat Research removed the hunting detection "Splunk Image File Disclosure via PDF Export in Classic Dashboard" from its content library in version 5.6.0 because the associated vulnerability had been patched. The content was updated on 2026-05-14.
The removed Splunk detection states that the image file disclosure issue affecting Splunk Enterprise 9.3.0, 9.2.3, and 9.1.6 had been patched in the latest Splunk release. The issue allowed low-privileged users without admin or power roles to view images on the host machine through classic dashboard PDF export.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.