Executive brief
Splunk Enterprise contains a flaw in its Search Processing Language 2 (SPL2) module management API that allows unprivileged users to delete all SPL2 modules across the entire system. SPL2 modules are components used to manage exported datasets and functions; deletion of these modules can disrupt search functionality, damage data integrity, and cause partial service outages affecting all users on the instance.
Technical details
The vulnerability is an improper access control flaw (CWE-862) in the SPL2 module management REST API. The API fails to properly authorize and validate module deletion requests, allowing users without "admin" or "power" roles to delete all SPL2 modules across all apps and users. The attack is network-reachable and requires only valid user authentication (no elevated privileges needed). An attacker can invoke the REST API to delete exported datasets and functions, degrading system integrity and availability. The issue affects Splunk Enterprise 10.4.0–10.4.1, 10.2.0–10.2.5, 10.0.0–10.0.8, and 9.4.0–9.4.13; patches are available in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14.
Affected products
- Splunk Enterprise 10.4.0–10.4.1, 10.2.0–10.2.5, 10.0.0–10.0.8, 9.4.0–9.4.13
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Patches released in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14