External Control of File Name or Path in Splunk Enterprise - CVE-2025-20320
Published: July 9, 2025
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote user to delete arbitrary files within the Splunk directory.
The vulnerability exists due to application allows an attacker to control path of the files to delete on "User Interface - Views" page. A remote user can send a specially crafted HTTP request and delete arbitrary files within the Splunk directory.