Impact
An unauthenticated user who can read a trusted distributed search private key can forge an administrative session token against the distributed search authentication token endpoint, which does not require a signed request to identify a search peer. This flaw allows the attacker to gain full administrative access, read all data, alter system configuration, and potentially disrupt service availability. The weakness is a classic case of improper authentication as identified by CWE-287.
Affected Systems
Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, and 9.4.14 are affected. These include any deployment of Splunk Enterprise that relies on distributed search and has a trusted distributed search private key exposed.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score is not available, suggesting no publicly known exploitation data. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires access to a distributed search private key; if that key is adequately protected the attack probability is low, but an internal actor or compromised system that can read the key could execute the attack readily.
OpenCVE Enrichment