CVE-2025-20386: Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade
In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20386?
CVE-2025-20386 is rated as a high severity vulnerability.
How do I fix CVE-2025-20386?
To fix CVE-2025-20386, upgrade to Splunk Enterprise for Windows version 10.0.2, 9.4.6, 9.3.8, or 9.2.10.
What types of users are affected by CVE-2025-20386?
Non-administrator users on Windows machines are affected by CVE-2025-20386 due to incorrect permission assignments.
What versions of Splunk Enterprise for Windows are vulnerable to CVE-2025-20386?
Versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10 of Splunk Enterprise for Windows are vulnerable to CVE-2025-20386.
What is the exploitability level of CVE-2025-20386?
CVE-2025-20386 is considered easily exploitable due to the improper permission assignments in the installation directory.