CVE-2025-20367
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2025-20367 is a reflected cross-site scripting (XSS) vulnerability in Splunk Enterprise and Splunk Cloud Platform, allowing a low-privileged user to execute unauthorized JavaScript code in another user's browser. The vulnerability is exploitable via the dataset.command parameter of the /app/search/table endpoint. Affected versions include Splunk Enterprise below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform below 9.3.2411.109, 9.3.2408.119, and 9.2.2406.122. It was publicly disclosed on October 1, 2025, with a CVSS v3.1 base score of 5.4 (Medium) (Splunk Advisory).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79 — Cross-site Scripting). A low-privileged attacker (without 'admin' or 'power' roles) can craft a malicious payload in the dataset.command parameter of the /app/search/table endpoint, which is then reflected and executed as JavaScript in the browser of another user who visits the crafted URL. Exploitation requires user interaction (the victim must click a malicious link or visit a crafted page) and low-level authentication, making this a reflected XSS attack pattern (CAPEC-591) (Splunk Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim user's browser session within Splunk. This can lead to session token theft, account hijacking, unauthorized actions performed on behalf of the victim (including accessing sensitive log data or dashboards), and potential privilege escalation if a high-privileged user (e.g., admin) is targeted. Confidentiality and integrity are both impacted, though availability is not directly affected (Splunk Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Splunk Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.037%, indicating a low probability of exploitation in the near term. Detection is available via Tenable Nessus plugin 266410 (Tenable).

Exploitation steps

  1. Reconnaissance: Identify a target Splunk Enterprise or Splunk Cloud Platform instance running a vulnerable version (Enterprise < 9.4.4/9.3.6/9.2.8; Cloud Platform < 9.3.2411.109/9.3.2408.119/9.2.2406.122).
  2. Obtain low-privileged access: Authenticate to the Splunk instance with any valid user account that does not hold the 'admin' or 'power' role.
  3. Craft malicious URL: Construct a URL targeting the /app/search/table endpoint with a malicious JavaScript payload injected into the dataset.command parameter (e.g., dataset.command=<script>malicious_code</script> or an encoded equivalent).
  4. Deliver payload: Trick a higher-privileged user (e.g., admin) into clicking the crafted link via phishing, social engineering, or embedding in a shared resource.
  5. Execute JavaScript: When the victim loads the crafted URL in their browser, the unsanitized payload is reflected and executed in their browser session, enabling session token theft, credential harvesting, or unauthorized actions within Splunk (Splunk Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET/POST requests to /app/search/table containing encoded JavaScript payloads or suspicious characters (e.g., <script>, javascript:, onerror=) in the dataset.command parameter.
  • Logs: Splunk access logs (splunkd_access.log) showing requests to /app/search/table with anomalous or encoded dataset.command values from low-privileged user accounts; repeated requests from the same source IP targeting this endpoint.
  • Browser/Session: Unexpected session token usage from unusual IP addresses or user agents following a victim's interaction with a suspicious link; unauthorized actions (e.g., dashboard modifications, data exports) performed under a high-privileged account shortly after a suspicious request.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 9.4.4, 9.3.6, and 9.2.8; Splunk Cloud Platform 9.3.2411.109, 9.3.2408.119, and 9.2.2406.122. Organizations should upgrade to these versions immediately. As interim measures, restrict user privileges carefully, monitor for suspicious activity targeting the /app/search/table endpoint, and consider implementing additional XSS protection mechanisms (e.g., Content Security Policy headers) (Splunk Advisory).

Community reactions

The vulnerability received coverage from several cybersecurity news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and CyberPress, which reported on it as part of a broader set of six Splunk flaws patched in October 2025. A Reddit thread in r/pwnhub also highlighted the issue. Community reaction was moderate, with no significant alarm given the medium severity score and lack of active exploitation. No notable individual researcher commentary or vendor statements beyond the official Splunk advisory were identified (SecurityOnline, GBHackers).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management