CVE-2025-20319

Remote Command Execution through Scripted Input Files in Splunk Enterprise

Severity
Medium 6.8
CVSS 3.1
Exploited
Not listed
EPSS
0.004
38.1th percentile
Discovered by
Not disclosed
Published
Jul 7, 2025
Assigned by cisco

Description

In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-privilege capability `edit_scripted` and `list_inputs` capability , could perform a remote command execution due to improper user input sanitization on the scripted input files.<br><br>See [Define roles on the Splunk platform with capabilities](https://docs.splunk.com/Documentation/Splunk/latest/Security/Rolesandcapabilities) and [Setting up a scripted input ](https://docs.splunk.com/Documentation/Splunk/9.4.2/AdvancedDev/ScriptSetup)for more information.

Weakness: CWE-78

Affected products

Vendor Product Category Matched by
Cisco Splunk Enterprise SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Splunk · Splunk Enterprise

Something wrong here?