CVE-2026-20255
Description
Splunk Enterprise and Cloud Platform are vulnerable to data exfiltration via crafted dashboards due to incomplete URL validation, allowing low-privileged users to send sensitive data to external servers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Splunk Enterprise and Cloud Platform are vulnerable to data exfiltration via crafted dashboards due to incomplete URL validation, allowing low-privileged users to send sensitive data to external servers.
Vulnerability
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a vulnerability exists in the URL validation for the external content dialog within classic dashboards. This allows a low-privileged user to craft a malicious dashboard that can send requests to untrusted domains [1].
Exploitation
An attacker with low privileges, who does not possess 'admin' or 'power' Splunk roles, can create a malicious classic dashboard. When a user interacts with this crafted dashboard, the incomplete URL validation allows requests to be sent to an external server, potentially exfiltrating sensitive data [1].
Impact
Successful exploitation allows a low-privileged user to exfiltrate sensitive data from Splunk to an external server. The scope of the compromise is limited to the data accessible through the crafted dashboard and the user's privileges [1].
Mitigation
Upgrade Splunk Enterprise to versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13, or higher. Splunk Cloud Platform instances are being patched. Workarounds include configuring the Dashboards Trusted Domains List to restrict external domains and reviewing role permissions for creating and editing classic dashboards [1].
AI Insight generated on Jun 10, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <10.3.2512.13, <10.2.2510.15, <10.1.2507.23, <9.3.2411.132
- Range: <10.2.4, <10.0.7, <9.4.12, <9.3.13
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- Splunk: Critical and High Severity Vulnerabilities Disclosed Together on June 10, 2026Vypr Intelligence · Jun 10, 2026