Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-20323


In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search `Bucket Copy Trigger` within the Splunk Archiver application. This is because of missing access controls in the saved searches for this app.


Published

2025-07-07T18:15:26.470

Last Modified

2025-07-21T20:53:33.120

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application splunk splunk < 9.1.10 Yes
Application splunk splunk < 9.2.7 Yes
Application splunk splunk < 9.3.5 Yes
Application splunk splunk < 9.4.3 Yes

References