CVE-2025-20368
Stored Cross-Site Scripting (XSS) through missing field warning messages in Saved Search and Job Inspector on Splunk Enterprise
Description
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through the error messages and job inspection details of a saved search. This could result in execution of unauthorized JavaScript code in the browser of a user.
INFO
Published Date :
Oct. 1, 2025, 5:15 p.m.
Last Modified :
Oct. 8, 2025, 8:22 p.m.
Remotely Exploit :
No
Source :
[email protected]
CVSS Scores
Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
---|---|---|---|---|---|---|
CVSS 3.1 | MEDIUM | d1c1063e-7a18-46af-9102-31f8928bc633 | ||||
CVSS 3.1 | MEDIUM | [email protected] | ||||
CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Update Splunk Enterprise to version 9.4.4 or later.
- Update Splunk Enterprise to version 9.3.6 or later.
- Update Splunk Enterprise to version 9.2.8 or later.
- Update Splunk Cloud Platform to the latest available version.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2025-20368
.
URL | Resource |
---|---|
https://advisory.splunk.com/advisories/SVD-2025-1003 | Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2025-20368
is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2025-20368
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2025-20368
vulnerability anywhere in the article.

-
The Cyber Express
Critical Splunk Vulnerabilities Expose Platforms to Remote JavaScript Injection and More
Splunk has disclosed six critical security vulnerabilities impacting multiple versions of both Splunk Enterprise and Splunk Cloud Platform. These Splunk vulnerabilities, collectively highlighting seri ... Read more

-
CybersecurityNews
Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code
Splunk has released patches for multiple vulnerabilities in its Enterprise and Cloud Platform products, some of which could allow attackers to execute unauthorized JavaScript code, access sensitive in ... Read more

-
Daily CyberSecurity
Splunk Fixes Six Flaws, Including Unauthenticated SSRF and XSS Vulnerabilities in Enterprise Platform
Splunk has released a series of security advisories addressing six vulnerabilities in Splunk Enterprise and Splunk Cloud Platform, ranging from medium to high severity. The flaws span improper access ... Read more
The following table lists the changes that have been made to the
CVE-2025-20368
vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
Initial Analysis by [email protected]
Oct. 08, 2025
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Added CPE Configuration OR *cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* versions from (including) 9.2.0 up to (excluding) 9.2.8 *cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* versions from (including) 9.3.0 up to (excluding) 9.3.6 *cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:* versions from (including) 9.4.0 up to (excluding) 9.4.4 *cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 9.2.2406 up to (excluding) 9.2.2406.123 *cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 9.3.2408 up to (excluding) 9.3.2408.118 *cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:* versions from (including) 9.3.2411 up to (excluding) 9.3.2411.108 Added Reference Type Cisco Systems, Inc.: https://advisory.splunk.com/advisories/SVD-2025-1003 Types: Vendor Advisory -
New CVE Received by [email protected]
Oct. 01, 2025
Action Type Old Value New Value Added Description In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privileged user that does not hold the admin or power Splunk roles could craft a malicious payload through the error messages and job inspection details of a saved search. This could result in execution of unauthorized JavaScript code in the browser of a user. Added CVSS V3.1 AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N Added CWE CWE-79 Added Reference https://advisory.splunk.com/advisories/SVD-2025-1003