An attacker can bypass access restrictions of Splunk Enterprise, via Sendemail REST API, in order to alter data.