Executive brief
Splunk Enterprise is a widely deployed data analytics platform used by organizations to search, analyze, and visualize machine-generated data. An unprivileged user can exploit a validation flaw in report notification handling to inject crafted data that causes Splunk Secure Gateway to make unauthorized REST API requests with system-level privileges. This allows the attacker to modify platform configuration, obtain passwordless session tokens, and access all data or compromise system integrity.
Technical details
This is a privilege escalation vulnerability (CWE-269/CWE-862) in Splunk Enterprise and Splunk Secure Gateway caused by insufficient validation of decoded report notification identifiers. An unauthenticated or low-privilege user can craft malicious report notification data that, when processed by Splunk Secure Gateway, results in unauthorized REST API requests to Splunk Enterprise using a system-level session token. The attacker can then modify platform configuration, bypass authentication to obtain session tokens without credentials, and access sensitive data. The vulnerability requires no network access beyond what is normally available to users and can be exploited without prior authentication as a privileged user. Patches are available in Splunk Enterprise 10.4.2, 10.2.6, 10.0.9, 9.4.14 and Splunk Secure Gateway 3.10.9, 3.9.23, 3.8.70.
Affected products
- Splunk Enterprise 10.4.0–10.4.1, 10.2.0–10.2.5, 10.0.0–10.0.8, 9.4.0–9.4.13
- Splunk Secure Gateway before 3.10.9, 3.9.23, and 3.8.70
Timeline
- 2026-08-19: disclosed