Impact
An authenticated user without the "admin" or "sc_admin" roles can write to App Key Value Store collections used by Splunk Secure Gateway alert and mobile-device subscription workflows. Because the collections grant unrestricted write access, such a user can modify alert configurations and recipient data, potentially disabling important alerts, misdirecting notifications, or creating false alerts. This flaw represents an improper authorization weakness that can undermine the integrity of the monitoring system.
Affected Systems
Splunk Enterprise versions earlier than 10.4.3, 10.2.7, 10.0.10, and 9.4.15, as well as Splunk Secure Gateway versions older than 3.10.11, 3.9.25, and 3.8.72 are affected.
Risk and Exploitability
The vendor rates this issue with a CVSS score of 6.3, indicating moderate severity, and the EPSS score is unavailable, so the current exploitation probability is unknown. It is not listed in the CISA KEV catalog. The vulnerability can only be exploited by an authenticated user who is not an administrator, so the attack vector is internal and requires valid credentials. If exploited, the attacker gains the ability to tamper with alert logic and notification settings, directly impacting the confidentiality, integrity, and availability of security monitoring.
OpenCVE Enrichment