Junglewise Threat Intelligence

CVE-2026-20257: Splunk Enterprise and Cloud Platform Data Exfiltration in Classic Dashboards

CVE-2026-20257 · Severity: medium · CVSS 5.7 · Published 2026-06-10

Technologies: Splunk Cloud Platform, Splunk Enterprise. Vendors: Splunk.

Executive brief

A vulnerability in Splunk's classic dashboard system allows a low-privileged user to steal sensitive information from higher-privileged users, such as administrators. By creating a specially crafted dashboard, an attacker can trick a victim's web browser into sending data to an unauthorized external server. This could lead to the exposure of internal data or administrative session details if a high-level user is persuaded to view the malicious dashboard.

Technical details

An improper input validation vulnerability exists in Splunk Web's classic dashboard panels. The component fails to fully validate CSS style attribute values, allowing an attacker to bypass the configured Trusted Domains List. A low-privileged attacker can craft a dashboard containing malicious style attributes that trigger outbound requests to an attacker-controlled domain when viewed by a victim. Exploitation requires the attacker to have basic user permissions and necessitates user interaction (phishing) to entice a high-privileged user to view the dashboard. Successful exploitation results in the exfiltration of sensitive data from the victim's browser context. Patches are available in Splunk Enterprise versions 10.2.4, 10.0.7, 9.4.12, 9.3.13, and 10.4.0.

Affected products

  • Splunk Splunk Enterprise Below 10.2.4, 10.0.7, 9.4.12, 9.3.13
  • Splunk Splunk Cloud Platform Below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, 9.3.2411.132

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats