CVE-2025-20367: Splunk
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
In Splunk Enterprise versions below 9.4.4, 9.3.6 and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.109, 9.3.2408.119 and 9.2.2406.122, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious payload through the `dataset.command` parameter of the `/app/search/table` endpoint, which could result in execution of unauthorized JavaScript code in the browser of a user.
Affected products
- Splunk Splunk: from 9.2.0, before 9.2.8 (fixed in 9.2.8); from 9.3.0, before 9.3.6 (fixed in 9.3.6); from 9.4.0, before 9.4.4 (fixed in 9.4.4)
- Splunk Splunk Cloud Platform: from 9.2.2406, before 9.2.2406.122 (fixed in 9.2.2406.122); from 9.3.2408, before 9.3.2408.119 (fixed in 9.3.2408.119); from 9.3.2411, before 9.3.2411.109 (fixed in 9.3.2411.109)
Published 2025-10-01. Last modified 2026-06-17.