Junglewise Threat Intelligence

CVE-2026-20258: Splunk Enterprise stored XSS in classic dashboard HTML panel

CVE-2026-20258 · Severity: high · CVSS 7.1 · Published 2026-06-10

Technologies: Splunk Cloud Platform, Splunk Enterprise. Vendors: Splunk.

Executive brief

A security vulnerability in Splunk's dashboarding feature allows a low-privileged user to embed malicious scripts into shared dashboards. If another user views the compromised dashboard, the script could execute in their browser, potentially allowing the attacker to steal sensitive session information or perform actions on the victim's behalf. This attack requires the victim to be tricked into interacting with a specific request, and it only affects systems where certain non-default web configurations are enabled.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Splunk Web component of Splunk Enterprise and Splunk Cloud Platform. The flaw is located in the classic dashboard HTML panel, where a low-privileged user (without 'admin' or 'power' roles) can inject malicious scripts. Exploitation requires the 'dashboard_html_allow_embeddable_content' setting in web.conf to be set to 'true' (it is 'false' by default). An attacker must also use social engineering to trick a victim into initiating a specific request. If successful, the attacker can execute arbitrary JavaScript in the context of the victim's session. Patches are available in Splunk Enterprise versions 10.2.4, 10.0.7, 9.4.12, 9.3.13, and various Splunk Cloud Platform releases.

Affected products

  • Splunk Splunk Enterprise 9.3.0 to 9.3.12, 9.4.0 to 9.4.11, 10.0.0 to 10.0.6, 10.2.0 to 10.2.3
  • Splunk Splunk Cloud Platform Below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, 9.3.2411.132

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats