CVE-2026-20258: Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could store a malicious script in a classic dashboard HTML panel, causing unauthorized JavaScript code to execute in the browser of another user.
The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The low-privileged user should not be able to exploit the vulnerability at will.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.4 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.12 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.3.13 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.3.2512.11 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.2.2510.15 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 10.1.2507.23 - Upgrade
Upgrade
Splunk Cloud Platformto a version that resolves this vulnerability.Fixed in 9.3.2411.132
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20258?
CVE-2026-20258 has a severity rating of 7.1, which is classified as high.
What types of Splunk versions are affected by CVE-2026-20258?
CVE-2026-20258 affects Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, as well as specific versions of Splunk Cloud Platform.
How can I mitigate CVE-2026-20258?
To mitigate CVE-2026-20258, update to the latest patched versions of Splunk Enterprise or Splunk Cloud Platform.
Who can exploit CVE-2026-20258?
CVE-2026-20258 can be exploited by low-privileged users not holding the 'admin' or 'power' Splunk roles.
What type of vulnerability is CVE-2026-20258?
CVE-2026-20258 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.