CVE-2025-20369

MEDIUM

Splunk <9.4.4, <9.3.6, <9.2.8 - DoS

Title source: llm

Description

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of service (DoS) attacks.

Scores

CVSS v3 4.6
EPSS 0.0005
EPSS Percentile 15.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

Classification

CWE
CWE-776 CWE-611
Status published

Affected Products (2)

splunk/splunk < 9.2.8
splunk/splunk_cloud_platform < 9.2.2406.123

Timeline

Published Oct 01, 2025
Tracked Since Feb 18, 2026