Impact
Splunk Enterprise versions earlier than 10.4.2 or 10.2.6 allow users without admin or power roles to delete SPL2 modules belonging to other users via the data management orchestrator. Because the orchestrator does not verify ownership before deletion, an attacker with a standard or power role can remove another user's modules, potentially disrupting searches and data ingestion. This reflects a broken object‑level authorization weakness (CWE‑639).
Affected Systems
Splunk Enterprise (Splunk) products running any supported version before 10.4.2 or before 10.2.6, but not those versions older than 10.2, are susceptible. This includes all 10.4.x, 10.2.x, and 10.0.x releases prior to the specified patch levels.
Risk and Exploitability
The CVSS score is 5.4, indicating a moderate risk. EPSS is not available, so the probability of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the REST API that the data management orchestrator uses; this inference is drawn from the description of the orchestrator interface. Attackers must have valid Splunk credentials but need not be administrators; a standard or power user can exploit the broken authorization to delete any other user's module, which could lead to loss of functionality or degraded performance.
OpenCVE Enrichment