CVE-2025-20300

Improper Access Control Lets Low-Privilege Users Suppress Read-Only Alerts in Splunk Enterprise

Severity
Medium 4.3
CVSS 3.1
Exploited
Not listed
EPSS
0.003
17.1th percentile
Discovered by
Not disclosed
Published
Jul 7, 2025
Assigned by cisco

Description

In Splunk Enterprise versions below 9.4.2, 9.3.5, 9.2.6, and 9.1.9 and Splunk Cloud Platform versions below 9.3.2411.103, 9.3.2408.112, and 9.2.2406.119, a low-privileged user that does not hold the "admin" or "power" Splunk roles, and has read-only access to a specific alert, could suppress that alert when it triggers. See [Define alert suppression groups to throttle sets of similar alerts](https://help.splunk.com/en/splunk-enterprise/alert-and-respond/alerting-manual/9.4/manage-alert-trigger-conditions-and-throttling/define-alert-suppression-groups-to-throttle-sets-of-similar-alerts).

Weakness: CWE-863

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (2)
  • Splunk · Splunk Enterprise
  • Splunk · Splunk Cloud Platform

Credit

Anton (therceman)