In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search `Bucket Copy Trigger` within the Splunk Archiver application. This is because of missing access controls in the saved searches for this app.
History

Mon, 21 Jul 2025 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
CPEs cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
Vendors & Products Splunk
Splunk splunk

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00026}

epss

{'score': 0.00029}


Mon, 07 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Jul 2025 18:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 9.4.3, 9.3.5, 9.2.7, and 9.1.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could turn off the scheduled search `Bucket Copy Trigger` within the Splunk Archiver application. This is because of missing access controls in the saved searches for this app.
Title Missing Access Control of Saved Searches in the Splunk Archiver app
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2025-07-07T17:48:03.961Z

Updated: 2025-07-07T18:05:58.100Z

Reserved: 2024-10-10T19:15:13.254Z

Link: CVE-2025-20323

cve-icon Vulnrichment

Updated: 2025-07-07T18:05:48.573Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-07T18:15:26.470

Modified: 2025-07-21T20:53:33.120

Link: CVE-2025-20323

cve-icon Redhat

No data.