PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-20252 Splunk CVE debrief

A vulnerability was discovered in Splunk Enterprise and Splunk Cloud Platform. A low-privileged user that does not hold the 'admin' or 'power' Splunk roles could send server-side requests to arbitrary internal destinations through the Dashboard Studio PDF export feature. The vulnerability exists due to trusted-domain validation using a prefix match that can be bypassed with attacker-controlled subdomains and because the PDF export service follows HTTP redirects automatically without re-validating each redirect target against the allowlist.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-10
Original CVE updated
2026-06-10
Advisory published
2026-06-10
Advisory updated
2026-06-10

Who should care

Users of Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132 should apply the necessary patches to prevent exploitation.

Technical summary

The vulnerability is caused by a prefix match in the trusted-domain validation and the automatic following of HTTP redirects by the PDF export service without re-validation. This allows a low-privileged user to send server-side requests to arbitrary internal destinations.

Defensive priority

HIGH

Recommended defensive actions

  • Apply patches for Splunk Enterprise versions: 10.2.4, 10.0.7, 9.4.12, and 9.3.13
  • Apply patches for Splunk Cloud Platform versions: 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132
  • Restrict access to the Dashboard Studio PDF export feature to only trusted users

Evidence notes

The CVE-2026-20252 vulnerability was identified in Splunk Enterprise and Splunk Cloud Platform. The vulnerability allows a low-privileged user to send server-side requests to arbitrary internal destinations.

Official resources

CVE-2026-20252 was published on 2026-06-10T18:16:40.630Z and modified on 2026-06-10T18:36:19.463Z.