Impact
An unauthenticated user can trigger a reload of Splunk Enterprise’s token‑signing keys via the REST API because the operation lacks an authentication check. Reloading the keys can invalidate existing authentication tokens or alter the signing mechanism, leading to denial of service or loss of authentication integrity where permissible keys are no longer considered valid. The weakness corresponds to missing authorization.
Affected Systems
Splunk Enterprise is affected when the version is 10.4.x and the build is older than 10.4.2. This includes all builds below 10.4.2 but does not impact any version prior to 10.4.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the lack of an EPSS value means exploitation likelihood is currently unknown, but the vulnerability is not listed in the CISA KEV catalog, so no confirmed exploits are documented. The attacker would typically need network access to the Splunk REST API endpoint, which, if exposed, could be abused without authentication. Because the operation is privileged, a successful exploitation could result in disruption of authentication services or denial of service, as the reloaded keys can invalidate current tokens or change the signing mechanism.
OpenCVE Enrichment