A vulnerability classified as critical has been found in Splunk Enterprise up to 9.1.9/9.2.6/9.3.4/9.4.2. Affected is an unknown function. The manipulation leads to os command injection.

This vulnerability is traded as CVE-2025-20319. It is possible to launch the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.