Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilitycloud-service-vulnerabilityidentity-authentication-vulnerability

Splunk Enterprise and Cloud Platform Vulnerabilities Allow Remote Code Execution and SSRF

Updated 24h agoFirst seen Oct 3, 20253 sources

Splunk has disclosed six critical security vulnerabilities affecting both Splunk Enterprise and Splunk Cloud Platform, exposing organizations to significant risks. The vulnerabilities include multiple cross-site scripting (XSS) flaws, an unauthenticated server-side request forgery (SSRF) vulnerability, and other weaknesses in Splunk’s web components. Two of the most notable XSS vulnerabilities are CVE-2025-20367, a reflected XSS in the /app/search/table endpoint, and CVE-2025-20368, a stored XSS in the Saved Search and Job Inspector features. Both XSS flaws can be exploited by low-privileged users to execute malicious JavaScript in the browsers of other users, potentially compromising user sessions and exposing sensitive data. The SSRF vulnerability, CVE-2025-20371, is particularly severe as it allows unauthenticated attackers to coerce Splunk into making REST API calls on behalf of authenticated high-privilege users, which could lead to further compromise of internal systems. These vulnerabilities affect multiple versions of Splunk Enterprise, specifically those below 10.0.1, 9.4.4, 9.3.6, and 9.2.8, as well as various versions of Splunk Cloud Platform. Successful exploitation of these flaws could allow attackers to gain unauthorized access, escalate privileges, and perform actions on behalf of legitimate users. Splunk has released patches addressing all six vulnerabilities and urges administrators to update their deployments immediately to mitigate the risks. The vulnerabilities highlight the importance of regular security assessments and prompt patch management in enterprise environments. Organizations using affected Splunk versions are advised to review their access logs for signs of exploitation and to apply the security updates without delay. The disclosure underscores the potential impact of web-based vulnerabilities in widely used security and analytics platforms. Security teams should also consider reviewing user permissions and monitoring for unusual activity in Splunk environments. The coordinated disclosure and rapid patching demonstrate the ongoing efforts by vendors and the security community to address critical flaws. These vulnerabilities, if left unpatched, could be leveraged in targeted attacks against organizations relying on Splunk for security monitoring and data analytics. The incident serves as a reminder of the evolving threat landscape and the need for vigilance in securing enterprise software. Splunk’s response includes detailed advisories and guidance for affected customers. The company has not reported any active exploitation in the wild at the time of disclosure, but the technical details provided could accelerate attempts by threat actors to develop exploits. Organizations are encouraged to stay informed about security advisories and to implement layered defenses to reduce the risk of compromise.

Share:
Splunk Enterprise and Cloud Platform Vulnerabilities Allow Remote Code Execution and SSRF
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Oct 1, 20259mo ago

Splunk begins patching cloud instances and recommends mitigations

Alongside the advisory, Splunk said it was actively patching affected Splunk Cloud Platform instances. The company also advised customers to upgrade and apply mitigations such as disabling Splunk Web when unnecessary and setting enableSplunkWebClientNetloc to false to reduce SSRF risk.

Splunk discloses high-severity SSRF as the most serious issue

Splunk identified CVE-2025-20371 as the most severe flaw in the October 2025 bundle, warning that an unauthenticated attacker could trigger blind SSRF and, under specific conditions, make REST API calls as a high-privileged user. The issue affected several Splunk Enterprise releases and some Splunk Cloud Platform builds.

Splunk releases patches for six Enterprise and Cloud Platform flaws

On 2025-10-01, Splunk issued security updates for six vulnerabilities affecting Splunk Enterprise and Splunk Cloud Platform, with severities ranging from medium to high. The fixes covered SSRF, XSS, information disclosure, XXE, and denial-of-service issues across multiple supported versions.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Splunk Enterprise and Cloud Platform Vulnerabilities Allow Remote Code Execution and SSRF | Mallory