Impact
In Splunk Enterprise versions below 10.4.2 and 10.2.6, the SPL2 module management REST API does not properly authorize delete requests, allowing users who do not hold the admin or power roles to remove all SPL2 modules across every app and user. This can erase exported datasets, functions, and other configurations, compromising data integrity and causing partial service disruption.
Affected Systems
Splunk Enterprise installations on any release prior to 10.4.2, 10.2.6, 10.0.9, or 9.4.14 are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity, while the EPSS score is not available, and the vulnerability is not listed in CISA KEV, so no public exploitation has been reported. Attackers can exploit the flaw remotely through the exposed REST API, requiring legitimate Splunk credentials and a role that is neither admin nor power.
OpenCVE Enrichment