Impact
The vulnerability allows an authenticated user who has the edit_spl2_module_permissions capability to retrieve permission grants for SPL2 modules via the REST API even when the user does not have read access to those modules. The affected components do not verify the user's ability to read the requested app before returning the permission data, effectively exposing privileged configuration information and enabling users to see or infer permissions they should not view. The weakness is classified as CWE‑639, an authorization bypass through improper access control.
Affected Systems
Splunk Enterprise installations with versions below 10.4.3, 10.2.7, or 10.0.10 are affected; version 9.4.x is not impacted. The vulnerable functionality resides in the REST API that serves SPL2 module permission grants.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a limited exploitation likelihood at present. The likely attack vector is through the REST API, requiring the attacker to have a role with edit_spl2_module_permissions and network access to the Splunk server. Because the flaw only exposes configuration data and not system control functions, the impact is limited to unauthorized information disclosure rather than remote code execution or denial of service.
OpenCVE Enrichment