Splunk Enterprise XSS Vulnerability Allows Attackers to Execute Unauthorized JavaScript

Splunk has disclosed a medium-severity cross-site scripting (XSS) vulnerability affecting multiple versions of its Enterprise and Cloud Platform products that could allow low-privileged attackers to execute malicious JavaScript code in users’ browsers.

The security vulnerability, tracked as CVE-2025-20297 and assigned a CVSSv3.1 score of 4.3, was published on June 2, 2025, and affects the dashboard PDF generation component through the pdfgen/render REST endpoint.

This vulnerability poses a significant risk to organizations relying on Splunk’s data analytics platform for security monitoring and business intelligence operations.

The reflected XSS vulnerability exists within Splunk Enterprise versions below 9.4.2, 9.3.4, and 9.2.6, as well as Splunk Cloud Platform versions below 9.3.2411.102, 9.3.2408.111, and 9.2.2406.118.

According to Splunk’s security advisory SVD-2025-0601, the flaw allows low-privileged users who do not possess “admin” or “power” roles to craft malicious payloads targeting the pdfgen/render REST endpoint.

When successfully exploited, this vulnerability enables attackers to execute unauthorized JavaScript code within the context of another user’s browser session.

The attack vector is particularly concerning because it requires minimal privileges and no user interaction, as indicated by the CVSS vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N.

This means attackers with basic network access and low-level authentication credentials can potentially compromise user sessions without requiring victims to click malicious links or perform specific actions.

The vulnerability is classified under CWE-79, the standard categorization for cross-site scripting flaws.

XSS Vulnerability

The vulnerability impacts a broad range of Splunk products across multiple version branches.

Splunk Enterprise users running versions 9.4.1, 9.3.0 through 9.3.3, and 9.2.0 through 9.2.5 are at risk, while version 9.1 remains unaffected.

The Splunk Web component serves as the primary attack surface for this vulnerability across all affected platforms.

Splunk Cloud Platform customers face similar exposure, with instances running below version 9.3.2411.102 in the 9.3.2411 branch, below 9.3.2408.111 in the 9.3.2408 branch, and below 9.2.2406.118 in the 9.2.2406 branch requiring immediate attention.

The vulnerability specifically targets instances with Splunk Web enabled, which represents the majority of production deployments given the component’s central role in dashboard management and user interface functionality.

Mitigations

Splunk recommends immediate upgrades to resolve the vulnerability, with fixed versions including Enterprise 9.4.2, 9.3.4, and 9.2.6.

Cloud Platform customers can expect automatic patches, as Splunk actively monitors and updates these instances.

For organizations unable to immediately upgrade, disabling Splunk Web presents a viable but potentially disruptive workaround that eliminates the attack surface entirely.

System administrators should review the web.conf configuration specification and consider disabling unnecessary Splunk Enterprise components as part of broader security hardening efforts.

While Splunk has not provided specific detection methods for this vulnerability, organizations should monitor access patterns to the pdfgen/render endpoint and review user privilege assignments to minimize potential exposure.

The disclosure follows Splunk’s responsible vulnerability management practices, providing clear upgrade paths and temporary mitigation options while maintaining transparency about affected product versions and potential impact scenarios.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

Mayura
Mayura
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Trending News

Related Stories