PT-2025-28230 · Splunk · Splunk Enterprise

Published

2025-07-07

·

Updated

2025-07-22

·

CVE-2025-20319

CVSS v2.0

7.7

High

VectorAV:A/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Splunk Enterprise versions prior to 9.4.3 Splunk Enterprise versions prior to 9.3.5 Splunk Enterprise versions prior to 9.2.7 Splunk Enterprise versions prior to 9.1.10
Description: A user with a role containing the high-privilege capabilities edit scripted and list inputs could perform remote command execution due to improper user input sanitization on scripted input files.
Recommendations: For versions prior to 9.4.3, update to version 9.4.3 or later. For versions prior to 9.3.5, update to version 9.3.5 or later. For versions prior to 9.2.7, update to version 9.2.7 or later. For versions prior to 9.1.10, update to version 9.1.10 or later.

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-10634
CVE-2025-20319

Affected Products

Splunk Enterprise