cbcvebase.
CVE-2025-20366
published 2025-10-01

CVE-2025-20366: In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a…

PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.41%
32.7th percentile
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in the background. If the low privileged user guesses the search job’s unique Search ID (SID), the user could retrieve the results of that job, potentially exposing sensitive search results. For more information see https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.0/manage-jobs/about-jobs-and-job-management and https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.0/manage-jobs/manage-search-jobs.

Affected

10 ranges
VendorProductVersion rangeFixed in
splunksplunk>= 9.2.0 < 9.2.89.2.8
splunksplunk>= 9.3.0 < 9.3.69.3.6
splunksplunk>= 9.4.0 < 9.4.49.4.4
splunksplunk_cloud_platform>= 9.2.2406 < 9.2.2406.1229.2.2406.122
splunksplunk_cloud_platform>= 9.3.2408 < 9.3.2408.1199.3.2408.119
splunksplunk_cloud_platform>= 9.3.2411 < 9.3.2411.1119.3.2411.111
splunksplunk_enterprise>= 10.0 < 10.0.010.0.0
splunksplunk_enterprise>= 9.2 < 9.2.89.2.8
splunksplunk_enterprise>= 9.3 < 9.3.69.3.6
splunksplunk_enterprise>= 9.4 < 9.4.49.4.4
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.