CVE-2025-20319
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2025-20319 is a remote command execution vulnerability in Splunk Enterprise caused by improper input sanitization on scripted input files. It affects Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10. The vulnerability was published on July 7, 2025, with a patch advisory released on July 21, 2025. It carries a CVSS v3.1 base score of 6.8 (Medium/High) (Splunk Advisory).

Technical details

The root cause is classified as CWE-78 (Improper Neutralization of Special Elements used in an OS Command — OS Command Injection). Exploitation requires a user account holding both the edit_scripted and list_inputs capabilities, which are considered high-privilege roles within Splunk. An attacker with these capabilities can craft malicious input in scripted input file configurations that, due to insufficient sanitization, results in arbitrary OS command execution on the Splunk Enterprise host. The attack vector is adjacent network (AV:A), meaning the attacker must be on the same network segment or have authenticated access to the Splunk interface (Splunk Advisory).

Impact

Successful exploitation allows an authenticated, high-privileged attacker to execute arbitrary commands on the underlying operating system hosting Splunk Enterprise. This results in high impact to confidentiality, integrity, and availability — an attacker could access sensitive log data and credentials stored in Splunk, modify or delete critical data, and disrupt Splunk services entirely. Given Splunk's role as a centralized log aggregation and SIEM platform, compromise could expose sensitive security telemetry and facilitate lateral movement across the monitored environment (Splunk Advisory).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Splunk Advisory). The EPSS score is approximately 0.062%, indicating a low current probability of exploitation in the wild. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high-privilege credentials (edit_scripted and list_inputs), which limits the attacker pool to insiders or accounts compromised through other means.

Exploitation steps

  1. Reconnaissance: Identify a Splunk Enterprise instance running a vulnerable version (below 9.4.3, 9.3.5, 9.2.7, or 9.1.10) accessible from the adjacent network.
  2. Credential Acquisition: Obtain credentials for a Splunk user account that holds both the edit_scripted and list_inputs capabilities — either through phishing, credential theft, or insider access.
  3. Access Scripted Inputs: Authenticate to the Splunk web interface or REST API and navigate to the scripted inputs configuration (Settings > Data Inputs > Scripts).
  4. Inject Malicious Payload: Create or modify a scripted input entry, injecting OS command injection payloads (e.g., shell metacharacters or command separators) into the script path or arguments field, exploiting the lack of proper input sanitization.
  5. Trigger Execution: Save the configuration and trigger the scripted input to execute, causing the injected OS commands to run in the context of the Splunk service account on the host system.
  6. Post-Exploitation: Use the achieved command execution to establish persistence, exfiltrate data, or pivot to other systems on the network (Splunk Advisory).

Indicators of compromise

  • Logs: Splunk internal logs (splunkd.log) showing unexpected script execution events or errors related to scripted inputs; audit logs recording creation or modification of scripted input configurations by unusual accounts.
  • Process: Unexpected child processes spawned by the Splunk service process (e.g., splunkd) such as bash, sh, cmd.exe, powershell.exe, curl, or wget with unusual arguments.
  • File System: New or modified script files in Splunk's $SPLUNK_HOME/etc/apps/ or scripted inputs directories with unexpected content or ownership.
  • Network: Outbound connections from the Splunk server to unknown external IP addresses or C2 infrastructure, particularly initiated by the Splunk service account.
  • Configuration: Unauthorized additions or changes to scripted input definitions visible in Splunk's inputs.conf files or via the REST API (/services/data/inputs/script).

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability: upgrade to Splunk Enterprise 9.4.3, 9.3.5, 9.2.7, or 9.1.10 as appropriate for your release branch (Splunk Advisory). As an interim workaround, administrators should immediately audit and restrict user roles to remove the edit_scripted and list_inputs capabilities from any accounts that do not strictly require them, applying the principle of least privilege. Additionally, audit all existing scripted inputs for suspicious or unauthorized entries, and monitor for unauthorized changes to scripted input configurations.

Community reactions

The vulnerability received standard coverage from threat intelligence aggregators and security databases shortly after disclosure on July 7, 2025. Rewterz published a threat advisory covering multiple Cisco/Splunk Enterprise vulnerabilities including CVE-2025-20319 (Rewterz Advisory). Community discussion on Reddit's r/Splunk was noted, though not specifically focused on this CVE. No significant researcher commentary or vendor statements beyond the official Splunk advisory have been identified.

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management