Splunk Enterprise <9.4.1 Privilege Escalation via Search Using Higher-Priv Account
CVE-2025-20231 Published on March 26, 2025
Sensitive Information Disclosure in Splunk Secure Gateway App
In Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, and versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform, a low-privileged user that does not hold the admin or power Splunk roles could run a search using the permissions of a higher-privileged user that could lead to disclosure of sensitive information.<br><br>The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The authenticated low-privileged user should not be able to exploit the vulnerability at will.
Weakness Type
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
Products Associated with CVE-2025-20231
stack.watch emails you whenever new vulnerabilities are published in Splunk or Splunk Secure Gateway. Just hit a watch button to start following.
Affected Versions
Splunk Enterprise:- Version 9.4 and below 9.4.1 is affected.
- Version 9.3 and below 9.3.3 is affected.
- Version 9.2 and below 9.2.5 is affected.
- Version 9.1 and below 9.1.8 is affected.
- Version 3.8 and below 3.8.38 is affected.
- Version 3.7 and below 3.7.23 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.