CVE-2025-20229: Remote Code Execution through file upload to “$SPLUNK_HOME/var/run/splunk/apptemp“ directory in Splunk Enterprise
In Splunk Enterprise versions below 9.3.3, 9.2.5, and 9.1.8, and Splunk Cloud Platform versions below 9.3.2408.104, 9.2.2406.108, 9.2.2403.114, and 9.1.2312.208, a low-privileged user that does not hold the "admin" or "power" Splunk roles could perform a Remote Code Execution (RCE) through a file upload to the "$SPLUNKHOME/var/run/splunk/apptemp" directory due to missing authorization checks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20229?
CVE-2025-20229 has a low severity rating but poses a significant risk of Remote Code Execution.
How do I fix CVE-2025-20229?
To mitigate CVE-2025-20229, upgrade to Splunk Enterprise version 9.3.3 or above, or Splunk Cloud Platform version 9.3.2408.104 or above.
Who is affected by CVE-2025-20229?
CVE-2025-20229 affects users of Splunk Enterprise versions below 9.3.3 and Splunk Cloud Platform versions below 9.3.2408.104.
What type of attack can CVE-2025-20229 enable?
CVE-2025-20229 can enable a low-privileged user to perform Remote Code Execution (RCE) on affected systems.
Are admin users vulnerable to CVE-2025-20229?
No, only low-privileged users without 'admin' or 'power' roles are vulnerable to CVE-2025-20229.