CVE-2025-20319

Remote Command Execution through Scripted Input Files in Splunk Enterprise

Severity
Medium 6.8
CVSS 3.1
Exploited
Not listed
EPSS
0.004
35.3th percentile
Discovered by
Not disclosed
Published
Jul 7, 2025
Assigned by cisco

Description

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-privilege capability `edit_scripted` and `list_inputs` capability , could perform a remote command execution due to improper user input sanitization on the scripted input files.<br><br>See [Define roles on the Splunk platform with capabilities](https://docs.splunk.com/Documentation/Splunk/latest/Security/Rolesandcapabilities) and [Setting up a scripted input ](https://docs.splunk.com/Documentation/Splunk/9.4.2/AdvancedDev/ScriptSetup)for more information.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by

No product mapping yet — this CVE is pending taxonomy review.

Vendor-reported affected versions (1)
  • Splunk · Splunk Enterprise