ZeroHour

CVE-2025-20297

mass

Authenticated XSS via pdfgen/render Endpoint in Splunk Enterprise and Splunk Cloud

CVSS 3.1
5.4 medium
EPSS
26%p98
Published
()
Modified
AI analysis

CVE-2025-20297 is a cross-site scripting flaw (CWE-79) in the pdfgen/render REST endpoint of Splunk Enterprise and Splunk Cloud Platform. An authenticated user who does not hold the admin or power roles can submit a crafted payload to this endpoint, and when the rendered output is viewed, unauthorized JavaScript executes in another user's browser (user interaction is required per the CVSS UI:R metric, with Scope Changed indicating the script runs outside the vulnerable component's scope). Successful exploitation gives the attacker JavaScript execution in a victim user's browser context, with limited confidentiality and integrity impact per the CVSS score of 5.4 (C:L/I:L/A:N). All Splunk Enterprise deployments in versions below 9.4.2, 9.3.4, and 9.2.6, and all Splunk Cloud Platform deployments below 9.3.2411.102, 9.3.2408.111, and 9.2.2406.118, are affected. No public proof-of-concept or KEV listing exists yet, but the elevated EPSS score (25.9% probability of exploitation within 30 days, 98th percentile) indicates a materially heightened near-term exploitation risk.

What to do: Upgrade Splunk Enterprise to 9.4.2, 9.3.4, or 9.2.6 (matching your release branch) or later; Splunk Cloud Platform customers should verify their deployment has been updated to 9.3.2411.102, 9.3.2408.111, or 9.2.2406.118 as applicable. Until patched, restrict access to the pdfgen/render REST endpoint and review which low-privileged accounts can reach it, since the flaw is triggered by non-admin/non-power users. Although the flaw is not yet in CISA KEV and has no public PoC, the 25.9% EPSS (98th percentile) justifies prioritizing patching of internet-facing and widely shared deployments.

Affected
Splunk EnterpriseVersions below 9.4.2, 9.3.4, and 9.2.6 (i.e., 9.4.x, 9.3.x, and 9.2.x release paths prior to those fixes)
Splunk Cloud PlatformVersions below 9.3.2411.102, 9.3.2408.111, and 9.2.2406.118
Estimated exposure
mass≈tens of thousands of internet-exposed Splunk instances and plausibly millions of analyst users overall — Splunk is one of the most widely deployed enterprise SIEM/observability platforms with a very large enterprise customer base, and public internet scans typically surface tens of thousands of exposed Splunk web interfaces; no exact install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Splunk Enterprise versions below 9.4.2, 9.3.4 and 9.2.6, and Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111 and 9.2.2406.118, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious payload through the pdfgen/render REST endpoint that could result in execution of unauthorized JavaScript code in the browser of a user.

Vendors
splunk
Products
splunk, splunk cloud platform
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.