Impact
The vulnerability arises from an incorrect permission assignment that allows users with the rest_properties_get capability to read encrypted stored credentials via the REST API in Splunk Enterprise. The flaw permits exposure of credential data that is meant to be protected, effectively leaking sensitive authentication material. The weakness is identified as an authorization error (CWE-732) and carries a CVSS score of 6.5, indicating moderate impact if exploited.
Affected Systems
Affected versions are Splunk Enterprise 10.4.1 and earlier, 10.2.5 and earlier, 10.0.8 and earlier, and 9.4.13 and earlier. Any deployment of these versions that assigns the rest_properties_get capability to a role is vulnerable. Upgrading to the publicly available patched releases (10.4.2, 10.2.6, 10.0.9, 9.4.14, or later) removes the flaw.
Risk and Exploitability
The exploitation requires a role with rest_properties_get, which most typical user roles may not possess. An attacker who can gain that capability or exploit privilege escalation can retrieve encrypted credentials through the REST endpoint. While EPSS data is not available and the issue is not listed in CISA's KEV catalog, the moderate CVSS score and the fact that the REST API is externally reachable make this a non‑negligible risk, especially in environments where credential privacy is critical.
OpenCVE Enrichment