CVE-2025-20297
massAuthenticated XSS via pdfgen/render Endpoint in Splunk Enterprise and Splunk Cloud
CVE-2025-20297 is a cross-site scripting flaw (CWE-79) in the pdfgen/render REST endpoint of Splunk Enterprise and Splunk Cloud Platform. An authenticated user who does not hold the admin or power roles can submit a crafted payload to this endpoint, and when the rendered output is viewed, unauthorized JavaScript executes in another user's browser (user interaction is required per the CVSS UI:R metric, with Scope Changed indicating the script runs outside the vulnerable component's scope). Successful exploitation gives the attacker JavaScript execution in a victim user's browser context, with limited confidentiality and integrity impact per the CVSS score of 5.4 (C:L/I:L/A:N). All Splunk Enterprise deployments in versions below 9.4.2, 9.3.4, and 9.2.6, and all Splunk Cloud Platform deployments below 9.3.2411.102, 9.3.2408.111, and 9.2.2406.118, are affected. No public proof-of-concept or KEV listing exists yet, but the elevated EPSS score (25.9% probability of exploitation within 30 days, 98th percentile) indicates a materially heightened near-term exploitation risk.
What to do: Upgrade Splunk Enterprise to 9.4.2, 9.3.4, or 9.2.6 (matching your release branch) or later; Splunk Cloud Platform customers should verify their deployment has been updated to 9.3.2411.102, 9.3.2408.111, or 9.2.2406.118 as applicable. Until patched, restrict access to the pdfgen/render REST endpoint and review which low-privileged accounts can reach it, since the flaw is triggered by non-admin/non-power users. Although the flaw is not yet in CISA KEV and has no public PoC, the 25.9% EPSS (98th percentile) justifies prioritizing patching of internet-facing and widely shared deployments.
| Splunk Enterprise | Versions below 9.4.2, 9.3.4, and 9.2.6 (i.e., 9.4.x, 9.3.x, and 9.2.x release paths prior to those fixes) |
| Splunk Cloud Platform | Versions below 9.3.2411.102, 9.3.2408.111, and 9.2.2406.118 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the pdfgen/render REST endpoint that could result in execution of unauthorized JavaScript code in the browser of a user.
- Vendors
- splunk
- Products
- splunk, splunk cloud platform
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.