Executive brief
Splunk Enterprise, a widely-used platform for searching and analyzing large volumes of machine data, contains a flaw in its Search Head Cluster member control endpoints that allows privileged users to change cluster state without proper authorization. A user with the list_search_head_clustering capability can send requests that bypass authorization checks, potentially disrupting cluster operations and causing service unavailability for organizations relying on Splunk for critical data monitoring and alerting.
Technical details
The vulnerability is an authorization bypass in Splunk Enterprise's Search Head Cluster member control REST API endpoints. The root cause is that these endpoints fail to enforce proper HTTP request type validation before applying read-only authorization checks, allowing state-changing operations to be performed by users who hold the high-privilege list_search_head_clustering capability. The attack requires the attacker to be an authenticated Splunk user with this specific role/capability, making it a privilege escalation or capability abuse scenario. An attacker can exploit this to send malicious requests to cluster endpoints and alter cluster state, resulting in denial of service. Patches are available in Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14 or later.
Affected products
- Splunk Enterprise below 10.4.2, 10.2.6, 10.0.9, and 9.4.14
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Patches released in versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14