Impact
In Splunk Enterprise, Edge Processor’s REST management endpoint can be accessed without authentication when Edge Processor is enabled. An unauthenticated attacker can retrieve pipeline configuration data through this endpoint, exposing potentially sensitive internal configuration details. The vulnerability is a manifestation of improper authentication controls and is classified as CWE-306.
Affected Systems
Splunk Enterprise deployments running versions 10.4, 10.2, 10.0, or 9.4 with Edge Processor enabled and older than the patched releases (10.4.2, 10.2.6, 10.0.9, 9.4.14) are affected. Versions earlier than 10.4 are not impacted, and instances that have disabled Edge Processor via the edge_processor_enabled setting are not vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk of unauthorized data disclosure. While no EPSS score is currently available and the vulnerability is not listed in the CISA KEV catalog, the simple unauthenticated REST access provides an obvious attack vector that can be used by any entity with network reach to the Splunk instance. Attackers could enumerate configuration components, learn internal pipelines, or gather information for more targeted attacks. The vulnerability is broadly exploitable because it does not require privileged credentials.
OpenCVE Enrichment