Vulnerabilities
- CVSS
- 5.3 Medium
- Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N- Risk score
- 42.4
- Published
- 2026-07-15
- Status
- Published
In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.2605.0, 10.4.2604.6, 10.3.2512.15, 10.2.2510.18, and 10.1.2507.24, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could view stored credential hashes when they access the `/servicesNS/-/-/storage/passwords` REST endpoint through the `|rest` Search Processing Language (SPL) command.<br><br>The exposure happens because the `|rest` SPL command returns the `encr_password` field in the results of the `/servicesNS/-/-/storage/passwords` REST endpoint.
Coverage 2
vulnerability
Splunk and Zoom have released patches to address several critical and high-severity vulnerabilities in their respective products. These flaws could allow attackers to steal credentials, access sensitive data, and potenti…
vulnerability
Multiple vulnerabilities have been discovered in Splunk products, including Splunk Cloud Platform and Enterprise versions. These vulnerabilities allow for data confidentiality and integrity breaches, as well as the poten…
Advisories and references