VYPR
High severity7.1NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026

CVE-2026-20258

CVE-2026-20258

Description

Splunk Enterprise and Cloud Platform are vulnerable to stored XSS via classic dashboard HTML panels, allowing low-privileged users to execute JavaScript in other users' browsers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Splunk Enterprise and Cloud Platform are vulnerable to stored XSS via classic dashboard HTML panels, allowing low-privileged users to execute JavaScript in other users' browsers.

Vulnerability

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user without 'admin' or 'power' roles can store a malicious script in a classic dashboard HTML panel. This can lead to unauthorized JavaScript code execution in another user's browser [1].

Exploitation

Exploitation requires the attacker to phish a victim, tricking them into initiating a request within their browser. A low-privileged user cannot exploit this vulnerability without user interaction [1].

Impact

An attacker can cause unauthorized JavaScript code to execute in the browser of another user. The scope and privilege level of the compromise depend on the victim's session and permissions within Splunk [1].

Mitigation

Upgrade Splunk Enterprise to versions 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13, or higher. Splunk is actively patching Splunk Cloud Platform instances. A workaround is to turn off Splunk Web or ensure dashboard_html_allow_embeddable_content in web.conf remains at its default value of false [1].

AI Insight generated on Jun 10, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1