Splunk has released updates for multiple vulnerabilities in its Enterprise and Cloud Platform products , some of which could allow attackers to execute JavaScript code , gain access to sensitive information , or cause a denial-of-service (DoS).

The notices, published on October 1, 2025, describe six security flaws, with severity ratings ranging from Moderate to High.
Splunk: Vulnerability Details
The most critical vulnerability is a Server-Side Request Forgery (SSRF) flaw, tracked as CVE-2025-20371 (with a CVSS score of 7.5/10). This vulnerability could allow an unauthenticated attacker to cause a blind SSRF , potentially allowing them to execute REST API calls on behalf of an authorized user with elevated privileges. Successful exploitation requires the enableSplunkWebClientNetloc setting to be enabled and may involve phishing to have the victim initiate a request from their browser.
See also: Hackers exploit Milesight routers to send phishing SMS

Two vulnerabilities involve JavaScript code execution, a form of cross-site scripting (XSS):
CVE-2025-20367 (CVSS: 5.7): A low-privileged user can craft a malicious payload via the dataset.command parameter of a specific endpoint, leading to JavaScript code execution in a browser .
CVE-2025-20368 (CVSS: 5.7): Similarly, a low-privileged user can inject a malicious payload into the error messages and job inspection details of a saved search, resulting in code execution.
Another significant flaw, CVE-2025-20366 (CVSS: 6.5), allows information disclosure. In this scenario, a low-privileged user, without 'admin' or 'power' roles, could gain access to the results of an administrative search job running in the background. If the attacker correctly guesses the job's unique Search ID (SID), they could retrieve potentially sensitive search results.
See also: 48+ Cisco Firewalls vulnerable to active zero-day vulnerability
The security update also addresses two moderate severity vulnerabilities that could impact system availability and integrity:
CVE-2025-20370 (CVSS: 4.9): A user with the change_authentication capability can send multiple LDAP bind requests to an internal endpoint, causing high CPU usage and a possible DoS condition requiring a reboot.
CVE-2025-20369 (CVSS: 4.6): A low-privileged user can perform XML External Entity (XXE) injection via the dashboard tab label field, which could also lead to a DoS attack.
The vulnerabilities affect multiple versions of Splunk Enterprise and Splunk Cloud Platform. Affected versions of Splunk Enterprise include those below 9.4.4, 9.3.6, and 9.2.8. Some also affect version 10.0.0.
See also: Vulnerabilities in Google Gemini allow data extraction
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Splunk has released updates and encourages customers to upgrade to the following or later versions:
| CVE ID | Vulnerability Type | CVSS 3.1 Score | Affected Product | Affected Versions | Fixed Versions |
|---|---|---|---|---|---|
| CVE-2025-20366 | Information Disclosure | 6.5 (Medium) | Splunk Enterprise | 9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.7 | 9.4.4 9.3.6 9.2.8 |
| Splunk Cloud Platform | Below 9.3.2411.111 Below 9.3.2408.119 Below 9.2.2406.122 | 9.3.2411.111 9.3.2408.119 9.2.2406.122 | |||
| CVE-2025-20367 | Cross-Site Scripting (XSS) | 5.7 (Medium) | Splunk Enterprise | 9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.7 | 9.4.4 9.3.6 9.2.8 |
| Splunk Cloud Platform | Below 9.3.2411.109 Below 9.3.2408.119 Below 9.2.2406.122 | 9.3.2411.109 9.3.2408.119 9.2.2406.122 | |||
| CVE-2025-20368 | Cross-Site Scripting (XSS) | 5.7 (Medium) | Splunk Enterprise | 9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.7 | 9.4.4 9.3.6 9.2.8 |
| Splunk Cloud Platform | Below 9.3.2411.108 Below 9.3.2408.118 Below 9.2.2406.123 | 9.3.2411.108 9.3.2408.118 9.2.2406.123 | |||
| CVE-2025-20369 | XXE Injection | 4.6 (Medium) | Splunk Enterprise | 9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.7 | 9.4.4 9.3.6 9.2.8 |
| Splunk Cloud Platform | Below 9.3.2411.108 Below 9.3.2408.118 Below 9.2.2406.123 | 9.3.2411.108 9.3.2408.118 9.2.2406.123 | |||
| CVE-2025-20370 | Denial of Service (DoS) | 4.9 (Medium) | Splunk Enterprise | 10.0.0 9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.7 | 10.0.1 9.4.4 9.3.6 9.2.8 |
| Splunk Cloud Platform | Below 9.3.2411.108 Below 9.3.2408.118 Below 9.2.2406.123 | 9.3.2411.108 9.3.2408.118 9.2.2406.123 | |||
| CVE-2025-20371 | Server-Side Request Forgery (SSRF) | 7.5 (High) | Splunk Enterprise | 10.0.0 9.4.0 – 9.4.3 9.3.0 – 9.3.5 9.2.0 – 9.2.7 | 10.0.1 9.4.4 9.3.6 9.2.8 |
| Splunk Cloud Platform | Below 9.3.2411.109 Below 9.3.2408.119 Below 9.2.2406.122 | 9.3.2411.109 9.3.2408.119 9.2.2406.122 |
Splunk has confirmed that it is actively updating all Splunk Cloud Platform instances and will notify customers upon completion.
For users who cannot apply the updates immediately, there are several workarounds available. It is recommended to disable Splunk Web unless necessary. For the SSRF flaw (CVE-2025-20371), administrators can mitigate the risk by setting enableSplunkWebClientNetloc to false in the web.conf file.
