Executive brief
Splunk On-Call (VictorOps) is an incident management app for Splunk that integrates alert and on-call workflows. In versions below 1.0.43, users without administrator privileges can read partially masked API keys from the app's key-value store, potentially allowing attackers to recover credentials and access external systems. This allows privilege escalation and unauthorized access to integrated services.
Technical details
The vulnerability is an information disclosure (CWE-312) caused by incomplete masking of API keys before storage in the Splunk App Key Value Store (KV Store). A non-admin, non-power user can query KV Store collections that contain the partially masked API key, allowing credential recovery. The attack requires network access to the Splunk instance and the ability to authenticate as a low-privileged user. An attacker can read and potentially reconstruct the full API key, gaining unauthorized access to the Splunk On-Call service and external integrations. The fix is available in version 1.0.43 and later.
Affected products
- Splunk On-Call below 1.0.43
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fix released in version 1.0.43