CVE-2025-20319: Remote Command Execution through Scripted Input Files in Splunk Enterprise
In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a user who holds a role that contains the high-privilege capability editscripted and listinputs capability , could perform a remote command execution due to improper user input sanitization on the scripted input files.<br><br>See Define roles on the Splunk platform with capabilities and Setting up a scripted input for more information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20319?
CVE-2025-20319 is classified as a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2025-20319?
To remediate CVE-2025-20319, upgrade to Splunk Enterprise versions 9.4.3, 9.3.5, 9.2.7, or 9.1.10 or later.
What systems are affected by CVE-2025-20319?
CVE-2025-20319 affects Splunk Enterprise versions prior to 9.4.3, 9.3.5, 9.2.7, and 9.1.10.
What capabilities allow exploitation of CVE-2025-20319?
Users with the 'edit_scripted' and 'list_inputs' high-privilege capabilities can exploit CVE-2025-20319.
What is the risk associated with CVE-2025-20319?
The risk of CVE-2025-20319 includes unauthorized remote command execution, potentially compromising system integrity.