Improper access control in Splunk Secure Gateway and Splunk Enterprise - CVE-2025-20383
Published: December 4, 2025
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to sensitive information.
The vulnerability exists due to improper access restrictions. A remote user can subscribe to mobile push notifications and receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.
Affected software
Splunk Enterprise
How to mitigate CVE-2025-20383
Splunk Enterprise - addressed in versions 9.2.10, 9.3.8, 9.4.6, 10.0.2