Executive brief
A vulnerability in Splunk's classic dashboards allows low-privileged users to create malicious links that redirect other users to external websites without warning. This could be used to trick victims into visiting attacker-controlled sites, potentially leading to the theft of sensitive information or data exfiltration. The issue affects both self-hosted Splunk Enterprise and Splunk Cloud Platform environments.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Splunk Web component's URL classifier for classic dashboards. The classifier only validates 'http://' and 'https://' schemes, failing to recognize protocol-relative URLs (e.g., '//attacker.com'). A low-privileged authenticated attacker can exploit this by embedding these URLs in dashboard drill-down links. When a victim clicks the link, Splunk fails to display the standard external-navigation warning dialog, facilitating stealthy redirection to an external domain. This can be used for data exfiltration or phishing. Fixes are available in Splunk Enterprise versions 10.2.4, 10.0.7, 9.4.12, 9.3.13, and 10.4.0.
Affected products
- Splunk Splunk Enterprise < 10.2.4, < 10.0.7, < 9.4.12, < 9.3.13
- Splunk Splunk Cloud Platform < 10.3.2512.13, < 10.2.2510.15, < 10.1.2507.23, < 9.3.2411.132
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory