Junglewise Threat Intelligence

CVE-2026-20255: Splunk Enterprise and Cloud Platform data exfiltration in Classic Dashboards

CVE-2026-20255 · Severity: medium · CVSS 5.7 · Published 2026-06-10

Technologies: Splunk Cloud Platform, Splunk Enterprise. Vendors: Splunk.

Executive brief

Splunk Enterprise and Splunk Cloud Platform are data analysis platforms used for monitoring and searching machine-generated data. A vulnerability in the 'classic dashboard' feature allows a low-privileged user to create a malicious dashboard that can steal sensitive information. If another user views this dashboard, their data could be sent to a server controlled by the attacker, potentially leading to the exposure of internal corporate information.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Splunk Web component's external content dialog. The root cause is incomplete URL validation, which fails to properly restrict requests to trusted domains. An attacker with low-privileged access can create a malicious classic dashboard that, when interacted with by another user, triggers requests to an untrusted external domain. This can be used to exfiltrate sensitive data. The attack requires network access, low-level authentication, and user interaction. Patches are available in Splunk Enterprise versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13, as well as various Splunk Cloud Platform updates.

Affected products

  • Splunk Splunk Enterprise Below 10.2.4, 10.0.7, 9.4.12, 9.3.13
  • Splunk Splunk Cloud Platform Below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, 9.3.2411.132

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats