CVE-2025-20369

MEDIUM

Splunk <9.4.4, <9.3.6, <9.2.8 - DoS

Title source: llm
STIX 2.1

Description

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a low privilege user that does not hold the "admin" or "power" Splunk roles could perform an extensible markup language (XML) external entity (XXE) injection through the dashboard tab label field. The XXE injection has the potential to cause denial of service (DoS) attacks.

Scores

CVSS v3 4.6
EPSS 0.0007
EPSS Percentile 20.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-776 CWE-611
Status published
Products (2)
splunk/splunk 9.2.0 - 9.2.8
splunk/splunk_cloud_platform 9.2.2406 - 9.2.2406.123
Published Oct 01, 2025
Tracked Since Feb 18, 2026