CVE-2025-20322 Details
Description
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, and Splunk Cloud Platform versions below 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119, an unauthenticated attacker could send a specially-crafted SPL search command that could trigger a rolling restart in the Search Head Cluster through a Cross-Site Request Forgery (CSRF), potentially leading to a denial of service (DoS).<br><br>The vulnerability requires the attacker to phish the administrator-level victim by tricking them into initiating a request within their browser. The attacker should not be able to exploit the vulnerability at will.<br><br>See [How rolling restart works](https://docs.splunk.com/Documentation/Splunk/9.4.2/DistSearch/RestartSHC) for more information.
A denial-of-service vulnerability has been identified in Splunk Enterprise versions prior to 9.4.3, 9.3.5, 9.2.7, and 9.1.10, as well as in Splunk Cloud Platform versions prior to 9.3.2411.104, 9.3.2408.113, and 9.2.2406.119. The vulnerability allows an unauthenticated attacker to send a specially-crafted SPL search command that triggers a rolling restart in the Search Head Cluster, potentially leading to service disruption. Exploitation requires phishing an administrator-level user to initiate the request in their browser.
Users of Splunk Enterprise should upgrade to versions 9.4.3, 9.3.5, 9.2.7, or 9.1.10. For Splunk Cloud Platform users, Splunk is actively monitoring and patching instances. Additionally, the vulnerability can be mitigated by turning off Splunk Web, especially for on-premises deployments.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-0705 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| splunk splunk | >= 9.1.0, < 9.1.10 >= 9.2.0, < 9.2.7 >= 9.3.0, < 9.3.5 >= 9.4.0, < 9.4.3 |
CPE
Remediation
| |
| splunk splunk cloud platform | >= 9.2.2406, < 9.2.2406.119 >= 9.3.2408, < 9.3.2408.113 >= 9.3.2411, < 9.3.2411.104 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 21, 2025 | Initial Analysis | [email protected] |
| Jul 7, 2025 | New CVE Received | [email protected] |