Impact
The Splunk App for Splunk Observability Cloud contains REST API endpoints that do not require the read_o11y_content capability. This omission lets a user who is not in the admin or power role trigger requests that the app forwards to Search Observability Cloud, exposing the access token stored for the app. With that token, the attacker can view all information and perform limited changes that the token permits, resulting in a breach of confidentiality and integrity. The flaw is a classic missing authorization vulnerability (CWE‑862).
Affected Systems
Splunk Enterprise deployments running versions earlier than 10.4.2, 10.2.6, or 10.0.9 with the Splunk App for Splunk Observability Cloud installed are vulnerable. Versions 9.4 and 9.3 are unaffected. Any user who is able to access the App’s REST endpoints with a non‑admin or non‑power role can exploit the weakness.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a high impact if exploited. No EPSS score is available, and the flaw is not listed in CISA’s Known Exploited Vulnerabilities catalog. The primary attack vector is via the App’s REST API, which an attacker can utilize if they have user access to the Splunk Enterprise instance. Although the exact exploitation probability is unknown, the combination of moderate‑high severity and the potential to exfiltrate sensitive data places it in a high‑risk category.
OpenCVE Enrichment