Impact
In older releases of Splunk Enterprise and Splunk Secure Gateway the default access control list for the Key Value Store REST API is improperly configured. Users without the "admin" or "power" roles can observe the contents of the Spacebridge asymmetric private key collection via the REST interface. This allows them to retrieve secrets that are intended to be protected and can lead to compromise of private key material used by Spacebridge.
Affected Systems
Splunk Enterprise versions lower than 10.4.2, 10.2.6, 10.0.9, and 9.4.14; Splunk Secure Gateway versions lower than 3.10.9, 3.9.23, and 3.8.70. The issue persists on instances upgraded from earlier deployments if migration of key material to the new storage has not been completed, leaving keys exposed with an insecure default ACL.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the vulnerability is only exploitable via the REST API by privileged users within the environment. The EPSS score is not available, and the flaw is not present in CISA's KEV catalog, suggesting that it has not been actively exploited at the time of analysis. Nevertheless, the ability to read protected keys poses a significant risk to confidentiality and integrity, making timely remediation a priority.
OpenCVE Enrichment