Splunk released security updates for Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway to address eight vulnerabilities, including two high-severity issues. The most serious flaw, CVE-2025-20229, can allow authenticated remote code execution through unauthorized file upload and execution, while CVE-2025-20231 can expose sensitive data because session data and authentication tokens may be logged in plaintext and protected with improper permissions. Splunk documentation for managing app and add-on objects is relevant because the attack surface includes application components and uploaded objects within Splunk environments.
The update also fixes several medium-severity weaknesses, including CSRF, an SPL security bypass with command execution, unauthorized access to sensitive data, and unauthorized system changes. Splunk further remediated vulnerabilities in bundled third-party components including idna, certifi, requests, urllib3, cryptography, axios, and Jinja2. Organizations using affected versions have been urged to upgrade promptly, and exposure from CVE-2025-20231 can also be reduced by disabling the Splunk Secure Gateway App until patches are applied.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Splunk released security updates for Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway to remediate eight vulnerabilities, including the high-severity flaws CVE-2025-20229 and CVE-2025-20231. The updates also addressed vulnerable third-party components such as idna, certifi, requests, urllib3, cryptography, axios, and Jinja2.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.