Junglewise Threat Intelligence

CVE-2026-20254: Splunk Enterprise CSS injection in classic dashboards

CVE-2026-20254 · Severity: medium · CVSS 5.7 · Published 2026-06-10

Technologies: Splunk Cloud Platform, Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used to monitor and search machine-generated data. A vulnerability in the dashboard component allows a low-privileged user to create a malicious dashboard that can steal sensitive information or credentials from higher-privileged users (like administrators) when they view it. This could lead to unauthorized access to sensitive corporate data or administrative accounts.

Technical details

A CSS injection vulnerability exists in Splunk Web's classic dashboards due to improper input validation in the 'Trusted Domains' security check. The component fails to fully validate inline style attribute values, allowing an attacker with low-level permissions to inject malicious CSS. When a victim with higher privileges (such as an 'admin' or 'power' user) views the crafted dashboard, the injected CSS can trigger outbound requests to untrusted domains, leading to credential exfiltration or sensitive data disclosure. This bypasses existing external content restrictions. Patches are available in Splunk Enterprise versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13.

Affected products

  • Splunk Splunk Enterprise Below 10.2.4, 10.0.7, 9.4.12, 9.3.13
  • Splunk Splunk Cloud Platform Below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, 9.3.2411.132

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory
  • 2026-06-10: patched

References

Related threats