CVE-2025-20366 Details
Description
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122, a low-privileged user that does not hold the admin or power Splunk roles could access sensitive search results if Splunk Enterprise runs an administrative search job in the background. If the low privileged user guesses the search job’s unique Search ID (SID), the user could retrieve the results of that job, potentially exposing sensitive search results. For more information see https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.0/manage-jobs/about-jobs-and-job-management and https://help.splunk.com/en/splunk-enterprise/search/search-manual/10.0/manage-jobs/manage-search-jobs.
A vulnerability exists in Splunk Enterprise versions prior to 9.4.4, 9.3.6, and 9.2.8, as well as in Splunk Cloud Platform versions prior to 9.3.2411.111, 9.3.2408.119, and 9.2.2406.122. The issue allows low-privileged users, who do not have admin or power roles, to access sensitive search results. This can occur if an administrative search job is running in the background. If the user manages to guess the unique Search ID (SID) of the job, they could retrieve the results, potentially exposing confidential information.
Users are advised to upgrade Splunk Enterprise to versions 9.4.4, 9.3.6, 9.2.8, or higher. For Splunk Cloud Platform instances, no action is needed as Splunk is actively monitoring and patching these versions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://advisory.splunk.com/advisories/SVD-2025-1001 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| splunk splunk | >= 9.2.0, < 9.2.8 >= 9.3.0, < 9.3.6 >= 9.4.0, < 9.4.4 |
CPE
Remediation
| |
| splunk splunk cloud platform | >= 9.2.2406, < 9.2.2406.122 >= 9.3.2408, < 9.3.2408.119 >= 9.3.2411, < 9.3.2411.111 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 8, 2025 | Initial Analysis | [email protected] |
| Oct 1, 2025 | New CVE Received | [email protected] |