Impact
A user with the read_o11y_content capability in Splunk Enterprise can issue outbound requests through the Splunk App for Splunk Observability Cloud’s REST API to an attacker‑controlled host, triggering a Server‑Side Request Forgery that exposes the configured Observability Cloud API token. This flaw stems from insufficient validation of the request destination and is classified as CWE‑918.
Affected Systems
Splunk Enterprise instances running versions below 10.4.3, 10.2.7, or 10.0.10, while 9.4.x versions are unaffected. The vulnerability surfaces only when the Splunk App for Splunk Observability Cloud is installed and a user possessing the read_o11y_content capability is able to invoke the REST API.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, with exploitation requiring privileged read_o11y_content access. EPSS data is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting that while potential for exploitation exists, the likelihood may remain limited. Nonetheless, an attacker who gains the stated role can redirect traffic to arbitrary hosts and capture an authentication token, compromising data security.
OpenCVE Enrichment