Impact
The vulnerability allows an unprivileged user to request the generation of signed payloads from the Splunk Secure Gateway REST API, a function that should be restricted to users with the 'admin' or 'power' Splunk roles. By signing attacker‑controlled payloads, a malicious user could bypass normal authorization checks and potentially execute or inject harmful commands. This weakness is a missing access control violation (CWE‑862).
Affected Systems
Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15 and Splunk Secure Gateway versions earlier than 3.10.11, 3.9.25, and 3.8.72 are affected. The issue is present in both the Enterprise platform and its Secure Gateway component, regardless of the deployment topology.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact if exploited, and the EPSS score is not available, which suggests limited public exploitation data. The vulnerability is not listed in the CISA KEV catalog. An attacker needs appropriate authenticated access to the Splunk platform but does not require administrative privileges. By leveraging the REST API, they can request signatures and create tampered payloads, potentially influencing downstream components that rely on signed data. Risk levels remain moderate but may increase if the attacker can inject malicious payloads that are accepted by downstream systems.
OpenCVE Enrichment