Cyber Security News

Splunk Enterprise XSS Vulnerability Let Attackers Execute Unauthorized JavaScript Code

A significant security vulnerability in the Splunk Enterprise platform could allow low-privileged attackers to execute unauthorized JavaScript code through a reflected Cross-Site Scripting (XSS) flaw. 

The vulnerability, tracked as CVE-2025-20297, affects multiple versions of Splunk Enterprise and Splunk Cloud Platform, prompting the company to issue immediate security updates.

The reflected XSS vulnerability resides within Splunk Enterprise’s dashboard PDF generation component, specifically targeting the pdfgen/render REST endpoint. 

Splunk Enterprise XSS Vulnerability

This security flaw enables attackers with minimal system privileges to craft malicious payloads that can execute arbitrary JavaScript code in victim browsers. 

The vulnerability is classified under CWE-79 (Cross-Site Scripting) and has been assigned a CVSSv3.1 score of 4.3, indicating a medium-severity risk level.

The attack vector is particularly concerning because it requires only low-level user privileges, excluding those with “admin” or “power” Splunk roles. 

This means that standard users with limited access can potentially exploit the vulnerability to compromise other users’ sessions. 

The CVSSv3.1 vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N indicates that the attack can be executed remotely with low complexity, requiring low privileges but no user interaction.

Risk FactorsDetails
Affected ProductsSplunk Enterprise, all releases below 9.4.2, 9.3.4, and 9.2.6Splunk Web component in Enterprise versions 9.4.1, 9.3.0 through 9.3.3, and 9.2.0 through 9.2.5
ImpactExecution of unauthorized JavaScript
Exploit PrerequisitesLow-privileged user (non-admin/power), Authenticated access to Splunk Web
CVSS 3.1 Score4.3 (Medium)

The vulnerability impacts a broad range of Splunk products across multiple version branches. 

For Splunk Enterprise, affected versions include all releases below 9.4.2, 9.3.4, and 9.2.6. Specifically, the Splunk Web component in Enterprise versions 9.4.1, 9.3.0 through 9.3.3, and 9.2.0 through 9.2.5 contains the vulnerability. 

Notably, Splunk Enterprise 9.1 versions remain unaffected by this security issue. Splunk Cloud Platform users are similarly impacted, with vulnerable versions including those below 9.3.2411.102, 9.3.2408.111, and 9.2.2406.118. 

The vulnerability specifically affects instances with Splunk Web enabled, as this component handles the PDF generation functionality where the XSS flaw exists. The bug was discovered by Klevis Luli from Splunk’s security team.

Mitigation Strategies

Splunk strongly recommends immediate upgrading to patched versions to address this vulnerability. For Enterprise users, the recommended fix versions are 9.4.2, 9.3.4, 9.2.6, or higher. 

The company is actively monitoring and automatically patching affected Splunk Cloud Platform instances to ensure customer security.

As an interim workaround, organizations can disable Splunk Web functionality entirely, effectively eliminating the attack vector since the vulnerability specifically targets the web interface’s PDF generation component. 

This mitigation can be implemented through the web.conf configuration file, though it may significantly impact user experience and dashboard functionality.

Security teams should prioritize this update given the potential for session hijacking and unauthorized code execution. While the vulnerability requires authenticated access, the low privilege requirements make it accessible to a broader range of potential attackers. 

Organizations should also review their user privilege assignments and consider implementing additional monitoring around the pdfgen/render endpoint until patches are fully deployed across their Splunk infrastructure.

Live Credential Theft Attack Unmask & Instant Defense – Free Webinar

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

28 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

10 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

11 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

12 hours ago