Executive brief
Cisco Talos Intelligence for Enterprise Security Cloud is a Splunk add-on that provides threat intelligence enrichment for security operations. An unauthenticated attacker can access the add-on's OpenAPI specification file through unprotected web paths, exposing details about the REST API endpoints and authentication mechanisms. This reconnaissance capability could be leveraged by an attacker to plan further attacks against the add-on or broader Splunk infrastructure.
Technical details
The vulnerability is an information disclosure flaw (CWE-200) in Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3. The root cause is improper access control on static file paths served by Splunk Web: the generated OpenAPI specification is accessible without authentication. An attacker can make unauthenticated network requests to retrieve the specification file via standard HTTP requests to known Splunk Web static file paths. The exposed OpenAPI spec reveals the add-on's REST API endpoint structure and authentication model, enabling reconnaissance for subsequent attacks. Affected versions below 1.0.3 should be upgraded to version 1.0.3 or later to remediate the issue. Alternatively, the add-on can be disabled or removed as a temporary mitigation.
Affected products
- Cisco Talos Intelligence for Enterprise Security Cloud below 1.0.3
Timeline
- 2026-08-19: disclosed