Junglewise Threat Intelligence

CVE-2026-20252: Splunk Enterprise SSRF in Dashboard Studio PDF export

CVE-2026-20252 · Severity: high · CVSS 7.6 · Published 2026-06-10

Technologies: Splunk Cloud Platform, Splunk Enterprise. Vendors: Splunk.

Executive brief

A vulnerability in Splunk's dashboard reporting tool allows users with low-level access to trick the server into making unauthorized requests to internal systems. This could allow an attacker to probe private internal networks or access sensitive data that is not intended to be public. The issue affects both the self-hosted Splunk Enterprise and the Splunk Cloud Platform.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the Dashboard Studio PDF export feature of Splunk Web. The flaw is caused by two primary issues: the trusted-domain validation mechanism uses a prefix match that can be bypassed using attacker-controlled subdomains (e.g., docs.splunk.com.attacker.com), and the PDF export service automatically follows HTTP redirects without re-validating the new destination against the allowlist. An authenticated, low-privileged user can exploit this to send arbitrary requests to internal destinations. Patches are available for Splunk Enterprise (10.2.4, 10.0.7, 9.4.12, 9.3.13) and various Splunk Cloud Platform versions.

Affected products

  • Splunk Splunk Enterprise Below 10.2.4, 10.0.7, 9.4.12, 9.3.13
  • Splunk Splunk Cloud Platform Below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, 9.3.2411.132

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory
  • 2026-06-10: patched

References

Related threats