Splunk Enterprise Missing Access Control Vulnerability in Archiver App

Vulnerability

A vulnerability exists in Splunk Enterprise versions prior to 9.4.3, 9.3.5, 9.2.7, and 9.1.10, allowing low-privileged users without 'admin' or 'power' roles to disable the scheduled 'Bucket Copy Trigger' search in the Splunk Archiver application. This issue arises from inadequate access controls on saved searches within the app.

Impact

Exploitation of this vulnerability allows low-privileged users to disable a scheduled search, potentially disrupting data management processes that rely on the 'Bucket Copy Trigger' functionality.

Remediation

Users can upgrade to Splunk Enterprise versions 9.4.3, 9.3.5, 9.2.7, 9.1.10, or higher. Alternatively, the Splunk Archiver app can be disabled without impacting other functionalities.

Added: Jul 7, 2025, 6:25 PM
Updated: Jul 7, 2025, 6:25 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
5.2
remediation
8.3
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.