Status: UPDATED | Advisory ID: CVE-2026-20258
| CVE | CVE-2026-20258 |
| CVSS Score / Version | 7.1 (High) / CVSS v3.1 |
| Updated | 2026-06-17 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is low; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Splunk splunk and Splunk splunk_cloud_platform |
| Classified as | CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Splunk | splunk | ||
| Splunk | splunk_cloud_platform |
| Subsystems | General OT |
| Sectors | Multiple |
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could store a malicious script in a classic dashboard HTML panel, causing unauthorized JavaScript code to execute in the browser of another user.
The vulnerability requires the attacker to phish the victim by tricking them into initiating a request within their browser. The low-privileged user should not be able to exploit the vulnerability at will. (NVD)
Monitor Splunk's web page for any future patch releases. See vendor advisory link below.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-20258 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-20258 |
| Vendor advisory | https://advisory.splunk.com/advisories/SVD-2026-0608 |