Executive brief
Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching machine-generated data. A security flaw in the web interface allows high-privileged users to reassign the ownership of saved searches to users outside of their authorized scope. This could lead to unauthorized access to sensitive search results or reports by users who should not have permission to view them.
Technical details
An improper access control vulnerability (CWE-284) exists in the Splunk Web component of Splunk Enterprise and Splunk Cloud Platform. The vulnerability resides in the ownership reassignment endpoint, which fails to properly validate the scope of the target user. An attacker with a role containing the 'edit_saved_search_owner' capability can exploit this to reassign saved searches to users outside their authorized administrative scope. This can lead to unauthorized data exposure if the new owner gains access to search results they were previously restricted from viewing. The issue is resolved in Splunk Enterprise versions 10.4.0, 10.2.4, 10.0.7, and various Splunk Cloud Platform maintenance releases.
Affected products
- Splunk Splunk Enterprise 10.2.0 to 10.2.3, 10.0.0 to 10.0.6
- Splunk Splunk Cloud Platform Below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, 9.3.2411.131
Timeline
- 2026-06-10: disclosed
- 2026-06-10: patched
- 2026-06-10: advisory