Impact
The vulnerability allows a user lacking admin or power roles to use a supplied job identifier to fetch detailed information from any search job of other users via the Splunk Enterprise REST API. The accessed data includes query text, metadata, full results, and preview results. The weakness stems from insufficient ownership validation in the API. The impact is the unintended disclosure of confidential search data and related metadata to unauthorized personnel.
Affected Systems
Splunk Enterprise is affected when running any of the following versions: all releases prior to 10.4.3, 10.2.7, 10.0.10, and 9.4.15. These versions lack the necessary checks to prevent non‑privileged users from accessing information belonging to other users.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The exploit probability is not quantified by EPSS, and the vulnerability is currently not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported. The likely attack vector is remote, leveraging authenticated API calls, and requires only the ability to craft a request with a job ID. An attacker with a non‑admin account could simply request the job ID for a target job and retrieve its full contents.
OpenCVE Enrichment