VYPR
Medium severity4.3NVD Advisory· Published Dec 3, 2025· Updated Jun 17, 2026

CVE-2025-20383

CVE-2025-20383

Description

In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Splunk/Splunk Enterprisellm-fuzzy2 versions
    <10.0.2, <9.4.6, <9.3.8, <9.2.10+ 1 more
    • (no CPE)range: <10.0.2, <9.4.6, <9.3.8, <9.2.10
    • (no CPE)range: 10.0
  • Splunk/Splunk Secure Gatewayllm-fuzzy3 versions
    <3.9.10, <3.8.58, <3.7.28+ 2 more
    • (no CPE)range: <3.9.10, <3.8.58, <3.7.28
    • cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*range: >=3.7.0,<3.7.28
    • (no CPE)range: 3.9
  • cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
    Range: >=9.2.0,<9.2.10
  • cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*range: >=9.3.2411,<9.3.2411.120
    • (no CPE)range: 10.1.2507

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.