vulnerability
Splunk: CVE-2021-31559: S2S TcpToken authentication bypass
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:P/A:N) | May 3, 2022 | Apr 7, 2025 | May 27, 2026 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
May 3, 2022
Added
Apr 7, 2025
Modified
May 27, 2026
Description
A crafted request bypasses S2S TCP Token authentication writing arbitrary events to an index in Splunk Enterprise Indexer 8.1 versions before 8.1.5 and 8.2 versions before 8.2.1. The vulnerability impacts Indexers configured to use TCPTokens. It does not impact Universal Forwarders. See Enable a receiver for more information on configuring an indexer to listen for UF traffic. See Control forwarder access for more information on securing UF to Indexer traffic with TcpTokens. When Splunk forwarding is secured using TLS, the attack requires compromising the certificate. As a partial mitigation and a security best practice, see Configure Splunk forwarding to use your own SSL certificates. Implementation reduces the severity to Medium.
Solution
splunk-upgrade-latest
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.