
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20319 is a remote command execution vulnerability in Splunk Enterprise caused by improper input sanitization on scripted input files. It affects Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10. The vulnerability was published on July 7, 2025, with a patch advisory released on July 21, 2025. It carries a CVSS v3.1 base score of 6.8 (Medium/High) (Splunk Advisory).
The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command — OS Command Injection). Exploitation requires a user account holding both the edit_scripted and list_inputs capabilities, which are considered high-privilege roles within Splunk. An attacker with these capabilities can craft malicious input in scripted input file configurations that, due to insufficient sanitization, results in arbitrary OS command execution on the Splunk Enterprise host. The attack vector is adjacent network (AV:A), meaning the attacker must be on the same network segment or have authenticated access to the Splunk interface (Splunk Advisory).
Successful exploitation allows an authenticated, high-privileged attacker to execute arbitrary commands on the underlying operating system hosting Splunk Enterprise. This results in high impact to confidentiality, integrity, and availability — an attacker could access sensitive log data and credentials stored in Splunk, modify or delete critical data, and disrupt Splunk services entirely. Given Splunk's role as a centralized log aggregation and SIEM platform, compromise could expose sensitive security telemetry and facilitate lateral movement across the monitored environment (Splunk Advisory).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Splunk Advisory). The EPSS score is approximately 0.062%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high-privilege credentials (edit_scripted and list_inputs), which limits the attacker pool to insiders or accounts compromised through other means.
edit_scripted and list_inputs capabilities — either through phishing, credential theft, or insider access.splunkd.log) showing unexpected script execution events or errors related to scripted inputs; audit logs recording creation or modification of scripted input configurations by unusual accounts.splunkd) such as bash, sh, cmd.exe, powershell.exe, curl, or wget with unusual arguments.$SPLUNK_HOME/etc/apps/ or scripted inputs directories with unexpected content or ownership.inputs.conf files or via the REST API (/services/data/inputs/script).Splunk has released patched versions addressing this vulnerability: upgrade to Splunk Enterprise 9.4.3, 9.3.5, 9.2.7, or 9.1.10 as appropriate for your release branch (Splunk Advisory). As an interim workaround, administrators should immediately audit and restrict user roles to remove the edit_scripted and list_inputs capabilities from any accounts that do not strictly require them, applying the principle of least privilege. Additionally, audit all existing scripted inputs for suspicious or unauthorized entries, and monitor for unauthorized changes to scripted input configurations.
The vulnerability received standard coverage from threat intelligence aggregators and security databases shortly after disclosure on July 7, 2025. Rewterz published a threat advisory covering multiple Cisco/Splunk Enterprise vulnerabilities including CVE-2025-20319 (Rewterz Advisory). Community discussion on Reddit's r/Splunk was noted, though not specifically focused on this CVE. No significant researcher commentary or vendor statements beyond the official Splunk advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."