
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20367 is a reflected cross-site scripting (XSS) vulnerability in Splunk Enterprise and Splunk Cloud Platform, allowing a low-privileged user to execute unauthorized JavaScript code in another user's browser. The vulnerability is exploitable via the dataset.command parameter of the /app/search/table endpoint. Affected versions include Splunk Enterprise below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform below 9.3.2411.109, 9.3.2408.119, and 9.2.2406.122. It was publicly disclosed on October 1, 2025, with a CVSS v3.1 base score of 5.4 (Medium) (Splunk Advisory).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79 — Cross-site Scripting). A low-privileged attacker (without 'admin' or 'power' roles) can craft a malicious payload in the dataset.command parameter of the /app/search/table endpoint, which is then reflected and executed as JavaScript in the browser of another user who visits the crafted URL. Exploitation requires user interaction (the victim must click a malicious link or visit a crafted page) and low-level authentication, making this a reflected XSS attack pattern (CAPEC-591) (Splunk Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim user's browser session within Splunk. This can lead to session token theft, account hijacking, unauthorized actions performed on behalf of the victim (including accessing sensitive log data or dashboards), and potential privilege escalation if a high-privileged user (e.g., admin) is targeted. Confidentiality and integrity are both impacted, though availability is not directly affected (Splunk Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Splunk Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.037%, indicating a low probability of exploitation in the near term. Detection is available via Tenable Nessus plugin 266410 (Tenable).
/app/search/table endpoint with a malicious JavaScript payload injected into the dataset.command parameter (e.g., dataset.command=<script>malicious_code</script> or an encoded equivalent)./app/search/table containing encoded JavaScript payloads or suspicious characters (e.g., <script>, javascript:, onerror=) in the dataset.command parameter.splunkd_access.log) showing requests to /app/search/table with anomalous or encoded dataset.command values from low-privileged user accounts; repeated requests from the same source IP targeting this endpoint.Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 9.4.4, 9.3.6, and 9.2.8; Splunk Cloud Platform 9.3.2411.109, 9.3.2408.119, and 9.2.2406.122. Organizations should upgrade to these versions immediately. As interim measures, restrict user privileges carefully, monitor for suspicious activity targeting the /app/search/table endpoint, and consider implementing additional XSS protection mechanisms (e.g., Content Security Policy headers) (Splunk Advisory).
The vulnerability received coverage from several cybersecurity news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and CyberPress, which reported on it as part of a broader set of six Splunk flaws patched in October 2025. A Reddit thread in r/pwnhub also highlighted the issue. Community reaction was moderate, with no significant alarm given the medium severity score and lack of active exploitation. No notable individual researcher commentary or vendor statements beyond the official Splunk advisory were identified (SecurityOnline, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."