VYPR
Unrated severityNVD Advisory· Published Dec 3, 2025· Updated Feb 26, 2026

Incorrect permission assignment on Splunk Enterprise for Windows during new installation or upgrade

CVE-2025-20386

Description

In Splunk Enterprise for Windows versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, a new installation of or an upgrade to an affected version can result in incorrect permissions assignment in the Splunk Enterprise for Windows Installation directory. This lets non-administrator users on the machine access the directory and all its contents.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Splunk/Splunk Enterprisellm-fuzzy2 versions
    <10.0.2 (or <9.4.6, <9.3.8, <9.2.10)+ 1 more
    • (no CPE)range: <10.0.2 (or <9.4.6, <9.3.8, <9.2.10)
    • (no CPE)range: 10.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.