CVE-2025-20298: Splunk Universal Forwarder
High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.
In Universal Forwarder for Windows versions below 9.4.2, 9.3.4, 9.2.6, and 9.1.9, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Universal Forwarder for Windows Installation directory (by default, C:\Program Files\SplunkUniversalForwarder). This lets non-administrator users on the machine access the directory and all its contents.
Affected products
- Splunk Universal Forwarder: from 9.1.0, before 9.1.9 (fixed in 9.1.9); from 9.2.0, before 9.2.6 (fixed in 9.2.6); from 9.3.0, before 9.3.4 (fixed in 9.3.4); from 9.4.0, before 9.4.2 (fixed in 9.4.2)
Published 2025-06-02. Last modified 2026-06-17.