Improper access control in Splunk Secure Gateway and Splunk Enterprise - CVE-2025-20383

 

Improper access control in Splunk Secure Gateway and Splunk Enterprise - CVE-2025-20383

Published: December 4, 2025


Vulnerability identifier: #VU119140
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20383
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain unauthorized access to sensitive information.

The vulnerability exists due to improper access restrictions. A remote user can subscribe to mobile push notifications and receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.


Affected software

Splunk Secure Gateway
Splunk Enterprise

How to mitigate CVE-2025-20383

Install updates from vendor's website.

Splunk Secure Gateway - addressed in versions 3.7.28, 3.8.58, 3.9.10
Splunk Enterprise - addressed in versions 9.2.10, 9.3.8, 9.4.6, 10.0.2

External References

Related Security Bulletins