Impact
In Splunk Enterprise, an attacker can acquire an embedded report token without authentication. When the token is used, a request to download the dispatch archive for the embedded report is accepted, and the system begins delivering the full archive before applying any access checks. Because the download is sent with the session context that owns the data, the attacker can retrieve the complete results of the report job, effectively bypassing the normal authorization controls. This flaw falls under CWE‑284, which describes incorrect authorization.
Affected Systems
The flaw affects Splunk Enterprise installations running versions earlier than 10.4.2, 10.2.6, 10.0.9, or 9.4.14. Any instance that provides embedded report functionality and accepts report tokens without imposing stricter authorization on archive downloads is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS base score of 9.4, indicating a very high severity. EPSS data is not available, but the lack of listing in the CISA KEV catalog does not diminish the severity because the attack requires only the report token and no elevated privileges. The likely attack vector is a remote request from an unauthenticated client that has been able to obtain a legitimate embedded report token, a scenario that can arise if report URLs are exposed or if an internal user inadvertently shares a token. Given this, the risk of exploitation remains high, and the integrity of data on the Splunk instance could be compromised if the flaw is leveraged.
OpenCVE Enrichment