Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Agentjacking Attack Hijacks AI Coding Agent for Mal
June 13, 2026
BugHunter: AI-Powered Bug Bounty Toolkit with Claude Free
June 13, 2026
Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero
June 13, 2026
Home/CyberSecurity News/Splunk Enterprise Flaws Let Attackers Execute Malicious Script
CyberSecurity News

Splunk Enterprise Flaws Let Attackers Execute Malicious Script

A series of security advisories, released on June 10, 2026, details multiple high and critical vulnerabilities within Splunk Enterprise. These flaws could enable attackers to execute malicious...

Sarah simpson
Sarah simpson
June 11, 2026 3 Min Read
11 0

A series of security advisories, released on June 10, 2026, details multiple high and critical vulnerabilities within Splunk Enterprise. These flaws could enable attackers to execute malicious scripts, exfiltrate sensitive data, and perform unauthorized file operations.

The most severe flaw, tracked as CVE-2026-20253, carries a CVSS score of 9.8 and affects Splunk Enterprise versions below 10.2.4 and 10.0.7.

The issue stems from missing authentication controls in a PostgreSQL sidecar service endpoint, allowing unauthenticated attackers to create or truncate arbitrary files.

This could lead to full system compromise, data destruction, or the persistence of malicious code without requiring user interaction.

Another high-severity vulnerability, CVE-2026-20258 (CVSS 7.1), involves stored cross-site scripting (XSS) in classic dashboards.

Splunk Enterprise Vulnerabilities

A low-privileged user can inject malicious JavaScript into dashboard HTML panels, which executes in the victim’s browser when they view the dashboard.

However, exploitation requires social engineering, as attackers must trick users into opening a crafted request.

Splunk also addressed a server-side request forgery (SSRF) vulnerability, CVE-2026-20252 (CVSS 7.6), in the Dashboard Studio PDF export feature.

The flaw allows attackers to send requests to internal systems by bypassing domain validation using crafted subdomains or redirect chains, could expose internal services or sensitive data.

Several medium-severity vulnerabilities (CVE-2026-20254, CVE-2026-20255, CVE-2026-20256, and CVE-2026-20257) affect classic dashboards and stem from improper input validation.

These issues enable data exfiltration via CSS injection, protocol-relative URLs, and insufficient validation of external content.

In these scenarios, attackers with low privileges can craft malicious dashboards that extract sensitive data when accessed by higher-privileged users.

CVE ID Severity Vulnerability Impact
CVE-2026-20258 High (7.1) Stored XSS in Classic Dashboard HTML panel Arbitrary JavaScript execution in victim browser
CVE-2026-20257 Medium (5.7) CSS input validation flaw Data exfiltration to external domains
CVE-2026-20256 Medium (5.7) Protocol-relative URL validation flaw Redirect-based data exfiltration
CVE-2026-20255 Medium (5.7) External content dialog validation flaw Data exfiltration to untrusted domains
CVE-2026-20254 Medium (5.7) CSS restriction bypass Credential and data exfiltration
CVE-2026-20253 Critical (9.8) Unauthenticated file creation/truncation Full compromise of affected systems
CVE-2026-20252 High (7.6) SSRF in Dashboard Studio PDF export Access to internal resources and data exposure

For example, an attacker could create a dashboard containing a hidden request to an external server.

When an administrator views the dashboard, sensitive session data or tokens could be silently transmitted to the attacker-controlled domain.

All vulnerabilities primarily impact Splunk Web components and require some level of user interaction or misconfiguration, such as enabling embeddable HTML content or insufficiently restricting trusted domains.

Splunk has released patches addressing these issues across supported versions. Users are advised to upgrade to Splunk Enterprise 10.4.0, 10.2.4, 10.0.7, 9.4.12, or 9.3.13, and to the corresponding Splunk Cloud Platform versions.

As mitigations, organizations should disable Splunk Web when not required, restrict dashboard-creation permissions, and enforce strict trusted-domain policies. Keeping the setting “dashboard_html_allow_embeddable_content” disabled also reduces the risk of XSS exploitation.

No detection signatures have been provided for these vulnerabilities, increasing the importance of timely patching and configuration hardening.

Given Splunk’s widespread use in security operations and log analysis, successful exploitation could grant attackers access to highly sensitive operational and security data, making these vulnerabilities particularly critical in enterprise environments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Hackers Abuse AWS/Google Cloud Logging to CloudTrail Evade

Next Post

Hackers Exploit VMware Binary to Sideload NIGHTFOR

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Hackers Abuse NinjaOne RMM to Bypass Malware Legitimate Software
June 12, 2026
Malicious npm Campaign Steals SSH Keys & Cloud Credentials
June 12, 2026
OnyxC2 MaaS Hackers Steal Credentials Malware-as-a-Service From
June 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Emy Elsamnoudy
Emy Elsamnoudy
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us