Database/Control plane, storage & DevOps
Splunk Enterprise Edge Processor sidecar: Prometheus metrics endpoint served without authentication
Impact
The Prometheus metrics endpoint on the Edge Processor SPL2 Preview sidecar accepts requests with no credentials, so any client that can route to the sidecar can pull its service metrics along with runtime and build metadata. The advisory describes disclosure only — no write path, no code execution, no log content. The practical value to an attacker is reconnaissance: exact build and runtime details of a logging component that typically sits close to the fleet's telemetry path. It matters most where the sidecar's port is reachable from tenant or workload networks rather than a dedicated management segment.
Who can reach it
Anyone with network reach to the sidecar's metrics port. No authentication and no Splunk account required. Limited to Splunk Enterprise 10.4 below 10.4.2; releases before 10.4 do not have the component.
What to do
Upgrade to Splunk Enterprise 10.4.2 per SVD-2026-0801, which restarts the Splunk service and the sidecar — no node reboot. Until then, restrict network access to the sidecar's metrics port to the monitoring collectors that need it.
References
Related entries
- Dell OpenManage Server Administrator (network-facing management service): OMSA is the in-band hardware management agentCVE-2026-81438 · Dell OpenManage Server Administrator (network-facing management service)High
- Linux kernel nfsd: uncapped POSIX ACL entry count drives an O(n^2) sort in the NFS serverCVE-2026-89695 · Linux kernel nfsd (NFSv4 POSIX ACL decoder, sort_pacl_range)High
- Linux kernel nfsd: crafted inter-server COPY compound reaches ops with a NULL filehandle and panics nfsdCVE-2026-89696 · Linux kernel nfsd (inter-server COPY, NFSD4_FH_FOREIGN compound dispatch)High
- Linux kernel nfsd: unbounded symlink target length lets a client force multi-MiB kmallocs per COMPOUND opCVE-2026-89699 · Linux kernel nfsd (NFSv4 CREATE symlink decoder, cr_datalen)High
- Linux kernel nfsd: async COPY samples the writeback error cursor late and reports failed copies as durableCVE-2026-89704 · Linux kernel nfsd (async server-side COPY, writeback error cursor in _nfsd_copy_file_range)High
- Linux kernel nfsd: write verifier not rotated when async COPY writeback fails, so COMMIT confirms lost dataCVE-2026-89706 · Linux kernel nfsd (async COPY write verifier rotation, nn->writeverf)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.