Cross-Site Request Forgery Vulnerability in Splunk Enterprise and Splunk Cloud Platform
CVE-2025-20322
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 7 July 2025
What is CVE-2025-20322?
In earlier versions of Splunk Enterprise and Splunk Cloud Platform, an unauthenticated attacker can exploit a cross-site request forgery vulnerability by crafting a malicious SPL search command. This may result in an unexpected rolling restart of the Search Head Cluster, leading to potential denial of service conditions. The attack requires social engineering techniques to trick an administrator into executing the malicious request in their browser, making it contingent on user interaction.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Splunk Enterprise 9.4 < 9.4.3
Splunk Enterprise 9.3 < 9.3.5
Splunk Enterprise 9.2 < 9.2.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved