Executive brief
Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching machine-generated data. A vulnerability in these platforms allows users with low-level access to view encrypted credential hashes that should be restricted to administrators. This could allow an internal user to potentially gain unauthorized access to other integrated systems by attempting to crack these hashes.
Technical details
An information disclosure vulnerability (CWE-200) exists in the Splunk REST API. Low-privileged users without 'admin' or 'power' roles can use the '|rest' Search Processing Language (SPL) command to query the '/servicesNS/-/-/storage/passwords' endpoint. The vulnerability is caused by the command incorrectly returning the 'encr_password' field in the results. An attacker with network access and valid low-privileged credentials can exploit this to obtain encrypted password hashes. Fixes involve upgrading to patched versions and, for Enterprise users, enabling 'mask_encr_password = true' in the limits.conf file.
Affected products
- Splunk Splunk Enterprise < 10.4.1, < 10.2.5, < 10.0.8, < 9.4.13
- Splunk Splunk Cloud Platform < 10.5.2605.0, < 10.4.2604.6, < 10.3.2512.15, < 10.2.2510.18, < 10.1.2507.24
Timeline
- 2026-07-15: disclosed
- 2026-07-15: advisory