Impact
A hard‑coded cryptographic key in the Splunk Secure Gateway companion app registration handler allows a user who does not hold the 'admin' or 'power' roles to register an arbitrary callback URL. The attacker can then cause the gateway to forward mobile user requests, including authentication tokens, to an attacker‑controlled URL. This results in token compromise and potential access to all data available to the affected mobile user. The vulnerability is characterized as a privilege escalation and credential theft flaw, given its reliance on a stored key and its ability to modify traffic flows.
Affected Systems
Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10, 3.9.24, and 3.8.71 are affected. These products are used to manage mobile connectivity and secure user sessions, meaning the flaw applies to any deployment using the affected releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS is not available, and the flaw is not listed in CISA KEV, suggesting no known widespread exploitation yet. The likely attack vector is via the Splunk user interface where a non‑privileged user can register a companion app. Exploitation requires the attacker to act as the user performing the registration, so remote or automated attacks are less likely, but the impact on data confidentiality is serious if the attack succeeds.
OpenCVE Enrichment