CVE-2025-20230
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Summary
CVE-2025-20230 is a vulnerability affecting Splunk Enterprise versions below 9.4.1, 9.3.3, 9.2.5, and 9.1.8, as well as versions below 3.8.38 and 3.7.23 of the Splunk Secure Gateway app on Splunk Cloud Platform. It allows a low-privileged user, who does not possess the "admin" or "power" roles, to edit and delete other users' data in App Key Value Store (KVStore) collections created by the Splunk Secure Gateway app. This occurs due to insufficient access control and incorrect ownership of the data in these KVStore collections, with the `nobody` user being the default owner.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.