Impact
This vulnerability allows a user who does not hold the "admin" or "power" Splunk roles to invoke privileged REST API endpoints in Splunk Secure Gateway. By bypassing the required authorization checks, the attacker can request that the gateway sign attacker‑controlled payloads, effectively enabling them to perform actions with elevated privileges. The primary impact is a privilege escalation that could lead to forging signatures and executing unauthorized requests within the Splunk ecosystem.
Affected Systems
The affected products are Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15, and Splunk Secure Gateway versions earlier than 3.10.11, 3.9.25, and 3.8.72. Users of those releases, regardless of administrative status, are susceptible if they are able to authenticate with a non‑"admin" or "power" Splunk role.
Risk and Exploitability
The CVSS score is 6.5, indicating a moderate severity risk. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The attack path requires an authenticated user with network access to the REST API; the attacker need not have elevated roles to call the vulnerable endpoints, making the exploitation relatively straightforward for any user who can reach the API. The lack of authorization enforcement means that the exploitation can be carried out remotely over the network or locally if the user has access to Splunk’s API endpoints.
OpenCVE Enrichment