Impact
The vulnerability is a flaw in Splunk Enterprise that allows unauthorized access to data or functionality due to improper access control. It is classified as CWE-284, indicating a weakness where restrictive access controls are not correctly enforced. Because the flaw can allow an attacker to bypass intended restrictions, it could lead to theft or modification of sensitive information, or elevation of privileges within the Splunk deployment.
Affected Systems
Splunk Enterprise builds that have not incorporated the fixes released in versions 10.4.3, 10.2.7, 10.0.10, or 9.4.15 are potentially vulnerable. The advisory does not enumerate explicitly which older revisions remain affected, but any deployment running code that predates these patches should be evaluated for risk.
Risk and Exploitability
Although no EPSS or CVSS score is available and it is not listed in the CISA KEV catalog, the flaw’s inherent nature as an improper access control mechanism allows an attacker who has network access to the Splunk deployment to bypass normal authorization checks. This could enable the attacker to read or modify data, or perform actions beyond the intended privilege level.
OpenCVE Enrichment