Improper Permissions in Splunk Universal Forwarder for Windows
CVE-2025-20387

8HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
3 December 2025

What is CVE-2025-20387?

The Splunk Universal Forwarder for Windows versions prior to 10.0.2, 9.4.6, 9.3.8, and 9.2.10 contain a flaw in the installation or upgrade process that may lead to improper permissions being assigned within the installation directory. This vulnerability allows non-administrator users unauthorized access to sensitive files and directories, potentially compromising the security of the system.

Affected Version(s)

Splunk Enterprise 10.0 < 10.0.2

Splunk Enterprise 9.4 < 9.4.6

Splunk Enterprise 9.3 < 9.3.8

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.