CVE-2026-20256: Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could cause data exfiltration through classic dashboards by redirecting a victim to an external site using a protocol-relative URL in a drill-down link.<br><br>The vulnerability exists because the URL classifier in classic dashboards only recognizes http:// and https:// schemes when checking for external URLs. Protocol-relative URLs such as //attacker.com bypass this check entirely, and Splunk Web does not show the external-navigation warning dialog to the victim.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.4 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.3.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.3.2512.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.15 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.23 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 9.3.2411.132
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20256?
CVE-2026-20256 has a medium severity rating of 5.7.
How do I fix CVE-2026-20256?
To address CVE-2026-20256, upgrade to Splunk Enterprise version 10.2.4 or later, or the corresponding version in Splunk Cloud Platform.
What kind of vulnerability is CVE-2026-20256?
CVE-2026-20256 is classified as an improper input validation vulnerability related to Protocol-Relative URLs.
Who is affected by CVE-2026-20256?
CVE-2026-20256 affects low-privileged users in Splunk Enterprise and Splunk Cloud Platform running on outdated versions.
What can an attacker do using CVE-2026-20256?
An attacker can exploit CVE-2026-20256 to cause data exfiltration through classic dashboards.