Impact
The flaw is a missing authorization weakness in the Splunk Secure Gateway REST API. API endpoints that deploy bundles, configure SAML, and manage companion apps can be accessed without Splunk Secure Gateway administrator privileges. An attacker who has permission to list storage passwords can retrieve signing secrets used for mobile‑device enrollment, breaking the trust chain for all devices and exposing them to compromise. The weakness maps to CWE‑862, Unauthorized Access.
Affected Systems
Affected products are Splunk Enterprise and Splunk Secure Gateway. Vulnerable Splunk Enterprise releases include any version prior to 10.4.2, 10.2.6, 10.0.9, or 9.4.14. Vulnerable Splunk Secure Gateway releases include any version prior to 3.10.10, 3.9.24, or 3.8.71.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact on confidentiality, integrity, and availability. No EPSS score is provided, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and requires only API access; an attacker must possess a role that can list storage passwords. Once that role is available, the attacker can call the vulnerable endpoints and harvest the signing secrets for all enrolled devices.
OpenCVE Enrichment