CVE-2025-20226

Risky command safeguards bypass in “/services/streams/search“ endpoint through “q“ parameter in Splunk Enterprise

Severity
Medium 5.7
CVSS 3.1
Exploited
Not listed
EPSS
0.004
36.5th percentile
Discovered by
Not disclosed
Published
Mar 26, 2025
Assigned by cisco

Description

In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8 and Splunk Cloud Platform versions below 9.3.2408.107, 9.2.2406.111, and 9.1.2308.214, a low-privileged user that does not hold the "admin" or "power" Splunk roles could run a saved search with a risky command using the permissions of a higher-privileged user to bypass the SPL safeguards for risky commands on the "/services/streams/search" endpoint through its "q" parameter. The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.

Weakness: CWE-200

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (2)
  • Splunk · Splunk Enterprise
  • Splunk · Splunk Cloud Platform

Credit

Anton (therceman)