In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.
History

Fri, 05 Dec 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk splunk
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*
cpe:2.3:a:splunk:splunk_secure_gateway:*:*:*:*:*:*:*:*
Vendors & Products Splunk splunk

Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Cloud Platform
Splunk splunk Enterprise
Splunk splunk Secure Gateway
Vendors & Products Splunk
Splunk splunk Cloud Platform
Splunk splunk Enterprise
Splunk splunk Secure Gateway

Wed, 03 Dec 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.0.2, 9.4.6, 9.3.8, and 9.2.10, and below 3.9.10, 3.8.58, and 3.7.28 of Splunk Secure Gateway app in Splunk Cloud Platform, a low-privileged user that does not hold the "admin" or "power" Splunk roles and subscribes to mobile push notifications could receive notifications that disclose the title and description of the report or alert even if they do not have access to view the report or alert.
Title Improper access control through push notifications for reports and alerts in Splunk Secure Gateway app
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2025-12-03T17:00:36.414Z

Updated: 2025-12-03T21:33:17.908Z

Reserved: 2024-10-10T19:15:13.264Z

Link: CVE-2025-20383

cve-icon Vulnrichment

Updated: 2025-12-03T21:33:08.317Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-03T17:15:50.567

Modified: 2025-12-05T18:30:13.090

Link: CVE-2025-20383

cve-icon Redhat

No data.