Impact
The vulnerability is a server‑side request forgery in the Splunk Secure Gateway report notification API. An authenticated user who is not an admin or power role can create a crafted notification that causes the gateway to issue an internal request to the Splunk Enterprise REST API using a system‑level session token. The gateway then modifies platform configuration. The attacker can subsequently generate a new session token without a password and gain full read‑write access to all data, effectively compromising system integrity.
Affected Systems
Affected products are Splunk Enterprise and Splunk Secure Gateway. For Splunk Enterprise versions prior to 10.4.2, 10.2.6, 10.0.9, or 9.4.14 any role below admin or power can trigger the flaw. Splunk Secure Gateway versions before 3.10.9, 3.9.23, or 3.8.70 are also vulnerable. No other products or versions were identified by the CNA.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact with ample privilege escalation potential. The EPSS value is unavailable, so historical exploitation data is unclear. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is likely network‑bound SSRF through the REST API of Secure Gateway, requiring the ability to send crafted report notifications, which is generally limited to users with reporting permissions but not to admin or power roles.
OpenCVE Enrichment