VYPR
Medium severity5.7NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026

CVE-2026-20257

CVE-2026-20257

Description

Splunk Enterprise and Cloud Platform are vulnerable to data exfiltration via crafted classic dashboards, allowing low-privileged users to trick higher-privileged users into revealing sensitive data.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Splunk Enterprise and Cloud Platform are vulnerable to data exfiltration via crafted classic dashboards, allowing low-privileged users to trick higher-privileged users into revealing sensitive data.

Vulnerability

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user can craft a classic dashboard that exfiltrates sensitive data from the browser of a higher-privileged user who views it. This is possible because classic dashboard panels do not fully validate style attribute values, allowing requests to reach external domains outside the configured Trusted Domains List [1].

Exploitation

Exploitation requires an attacker to phish a victim by tricking them into initiating a request within their browser. A low-privileged user, who does not hold the "admin" or "power" Splunk roles, must craft a malicious classic dashboard. The victim, a higher-privileged user, must then view this dashboard. The low-privileged user should not be able to exploit the vulnerability at will [1].

Impact

A successful exploitation allows a low-privileged user to exfiltrate sensitive data from the browser of a higher-privileged user. The scope of the compromise is limited to the data accessible within the victim's browser session and requires user interaction via phishing [1].

Mitigation

Splunk Enterprise should be upgraded to versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13, or higher. Splunk Cloud Platform instances are being actively monitored and patched. As a workaround, administrators can configure the Dashboards Trusted Domains List to restrict which external domains dashboards can load content from [1].

AI Insight generated on Jun 10, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1