Medium severity5.7NVD Advisory· Published Jun 10, 2026· Updated Jun 15, 2026
CVE-2026-20255
CVE-2026-20255
Description
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could craft a malicious classic dashboard that exfiltrates sensitive data to an external server.
The vulnerability exists because URL validation on the external content dialog is incomplete, which can allow for requests to untrusted domains when a user interacts with a crafted dashboard.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:splunk:splunk_cloud_platform:*:*:*:*:*:*:*:*range: >=9.3.2411,<9.3.2411.132
- (no CPE)range: <10.3.2512.13, <10.2.2510.15, <10.1.2507.23, <9.3.2411.132
- Range: <10.2.4, <10.0.7, <9.4.12, <9.3.13
Patches
Vulnerability mechanics
References
1- advisory.splunk.com/advisories/SVD-2026-0605nvdVendor Advisory
News mentions
2- Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious ScriptCyber Security News · Jun 11, 2026
- Splunk: Critical and High Severity Vulnerabilities Disclosed Together on June 10, 2026Vypr Intelligence · Jun 10, 2026