
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20322 is a Cross-Site Request Forgery (CSRF) vulnerability in Splunk Enterprise and Splunk Cloud Platform that allows an unauthenticated attacker to trigger a rolling restart of the Search Head Cluster (SHC), potentially causing a denial of service (DoS). It affects Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119. The vulnerability was disclosed on July 7, 2025, with a CVSS v3.1 base score of 4.3 (Medium) (Splunk Advisory).
The vulnerability is classified as CWE-352 (Cross-Site Request Forgery). An attacker crafts a malicious SPL (Search Processing Language) search command that, when executed in the browser context of an authenticated administrator, triggers an unintended rolling restart of the Search Head Cluster. Exploitation requires social engineering — the attacker must phish an administrator-level user and trick them into initiating the forged request within their browser session; the attacker cannot exploit this vulnerability directly or at will (Splunk Advisory).
Successful exploitation results in a limited availability impact: the Search Head Cluster undergoes an unintended rolling restart, temporarily disrupting Splunk search capabilities and services for all users relying on the affected cluster. There is no confidentiality or integrity impact — the vulnerability cannot be used to access, exfiltrate, or modify data. The scope is limited to the affected Splunk deployment and does not facilitate lateral movement (Splunk Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is further constrained by the requirement to successfully phish an administrator-level user (Splunk Advisory).
Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 9.4.3, 9.3.5, 9.2.7, and 9.1.10; Splunk Cloud Platform 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119. Organizations should upgrade to these versions immediately. As additional mitigations, administrators should enable multi-factor authentication (MFA) for all administrative accounts, train administrators to recognize phishing attempts, and monitor for unexpected SHC rolling restart events. Implementing network segmentation and restricting access to Splunk management interfaces can further reduce exposure (Splunk Advisory).
The vulnerability received routine coverage from security aggregators and vulnerability databases shortly after disclosure on July 7, 2025, including listings on Vulners, VulDB, CIRCL, and ENISA's EUVD. No notable researcher commentary, vendor statements beyond the official advisory, or significant social media discussion has been identified, consistent with the vulnerability's medium severity and limited exploitability (Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."