CVE 5.7 MEDIUM

Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise_CVE-2026-20256

5.7 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Description

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could cause data exfiltration through classic dashboards by redirecting a victim to an external site using a protocol-relative URL in a drill-down link.<br><br>The vulnerability exists because the URL classifier in classic dashboards only recognizes `http://` and `https://` schemes when checking for external URLs. Protocol-relative URLs such as `//attacker.com` bypass this check entirely, and Splunk Web does not show the external-navigation warning dialog to the victim.

Basic Information

ID CVE-2026-20256
Source cisco
Published Jun 10, 2026 at 17:15
Modified Jun 10, 2026 at 18:19

Affected Product

Vendor Splunk
Product Splunk Enterprise
Version 10.2
Affected Versions Splunk Splunk Enterprise 10.2
Splunk Splunk Enterprise 10.0
Splunk Splunk Enterprise 9.4
Splunk Splunk Enterprise 9.3
Splunk Splunk Cloud Platform 10.3.2512
Splunk Splunk Cloud Platform 10.2.2510
Splunk Splunk Cloud Platform 10.1.2507
Splunk Splunk Cloud Platform 9.3.2411

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.