Executive brief
Cisco Talos Intelligence for Enterprise Security Cloud is a Splunk app that enriches security data with threat intelligence. An authenticated user with specific permissions can exploit a server-side request forgery vulnerability to trick the app into making requests to attacker-controlled servers, potentially exposing authentication tokens and compromising the entire Splunk instance's data and system integrity.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) flaw (CWE-918) in the Talos intelligence enrichment REST API endpoint. An attacker with a role possessing the get_talos_enrichment capability can send a crafted request specifying an attacker-controlled destination, causing the vulnerable endpoint to make an outbound authenticated request to that server. This exposes Splunk management tokens that could compromise all relevant data and system integrity. The root cause is that the REST endpoint accepts the destination for authenticated Splunk management requests directly from user-supplied request data without proper validation. The vulnerability affects versions below 1.0.3, and a patch is available in version 1.0.3 or later.
Affected products
- Cisco Talos Intelligence for Enterprise Security Cloud below 1.0.3
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in version 1.0.3