Vulnerability Details CVE-2026-20254
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could craft a malicious classic dashboard that exfiltrates sensitive data to an external server when a higher-privileged user views it, bypassing the external content restriction through a Cascading Style Sheets (CSS) injection.<br><br>The Trusted Domains security check does not fully validate inline style attribute values, which can allow for outbound requests to untrusted domains and credential exfiltration when a victim views a crafted dashboard.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 16.5%
CVSS Severity
CVSS v3 Score 5.7
Products affected by CVE-2026-20254
-
cpe:2.3:a:splunk:splunk:10.0.0
-
cpe:2.3:a:splunk:splunk:10.0.1
-
cpe:2.3:a:splunk:splunk:10.0.2
-
cpe:2.3:a:splunk:splunk:10.0.3
-
cpe:2.3:a:splunk:splunk:10.0.4
-
cpe:2.3:a:splunk:splunk:10.0.5
-
cpe:2.3:a:splunk:splunk:10.2.0
-
cpe:2.3:a:splunk:splunk:10.2.1
-
cpe:2.3:a:splunk:splunk:10.2.2
-
cpe:2.3:a:splunk:splunk:9.3.0
-
cpe:2.3:a:splunk:splunk:9.3.1
-
cpe:2.3:a:splunk:splunk:9.3.10
-
cpe:2.3:a:splunk:splunk:9.3.11
-
cpe:2.3:a:splunk:splunk:9.3.12
-
cpe:2.3:a:splunk:splunk:9.3.2
-
cpe:2.3:a:splunk:splunk:9.3.3
-
cpe:2.3:a:splunk:splunk:9.3.4
-
cpe:2.3:a:splunk:splunk:9.3.5
-
cpe:2.3:a:splunk:splunk:9.3.6
-
cpe:2.3:a:splunk:splunk:9.3.7
-
cpe:2.3:a:splunk:splunk:9.3.8
-
cpe:2.3:a:splunk:splunk:9.3.9
-
cpe:2.3:a:splunk:splunk:9.4.0
-
cpe:2.3:a:splunk:splunk:9.4.1
-
cpe:2.3:a:splunk:splunk:9.4.10
-
cpe:2.3:a:splunk:splunk:9.4.11
-
cpe:2.3:a:splunk:splunk:9.4.2
-
cpe:2.3:a:splunk:splunk:9.4.3
-
cpe:2.3:a:splunk:splunk:9.4.4
-
cpe:2.3:a:splunk:splunk:9.4.5
-
cpe:2.3:a:splunk:splunk:9.4.6
-
cpe:2.3:a:splunk:splunk:9.4.7
-
cpe:2.3:a:splunk:splunk:9.4.8
-
cpe:2.3:a:splunk:splunk:9.4.9
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.1
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.10
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.11
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.12
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.15
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.16
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.17
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.19
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.20
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.4
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.6
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.1.2507.8
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.10
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.12
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.13
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.3
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.4
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.5
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.7
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.8
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.2.2510.9
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.3.2512
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.3.2512.10
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.3.2512.11
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.3.2512.5
-
cpe:2.3:a:splunk:splunk_cloud_platform:10.3.2512.6
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.102
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.103
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.104
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.107
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.108
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.109
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.111
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.112
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.116
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.117
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.120
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.121
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.123
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.124
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.127
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.128
-
cpe:2.3:a:splunk:splunk_cloud_platform:9.3.2411.130