PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-20252 Splunk CVE debrief

A vulnerability was discovered in Splunk Enterprise and Splunk Cloud Platform. A low-privileged user that does not hold the 'admin' or 'power' Splunk roles could send server-side requests to arbitrary internal destinations through the Dashboard Studio PDF export feature. The vulnerability exists due to trusted-domain validation using a prefix match that can be bypassed with attacker-controlled subdomains and because the PDF export service follows HTTP redirects automatically without re-validating each redirect target against the allowlist.

Vendor
Splunk
Product
Splunk Enterprise
CVSS
HIGH 7.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-10
Original CVE updated
2026-06-15
Advisory published
2026-06-10
Advisory updated
2026-06-15

Who should care

Users of Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132 should apply the necessary patches to prevent exploitation.

Technical summary

The vulnerability is caused by a prefix match in the trusted-domain validation and the automatic following of HTTP redirects by the PDF export service without re-validation. This allows a low-privileged user to send server-side requests to arbitrary internal destinations.

Defensive priority

HIGH

Recommended defensive actions

  • Apply patches for Splunk Enterprise versions: 10.2.4, 10.0.7, 9.4.12, and 9.3.13
  • Apply patches for Splunk Cloud Platform versions: 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132
  • Restrict access to the Dashboard Studio PDF export feature to only trusted users

Evidence notes

The CVE-2026-20252 vulnerability was identified in Splunk Enterprise and Splunk Cloud Platform. The vulnerability allows a low-privileged user to send server-side requests to arbitrary internal destinations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-20252 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-20252

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-20252 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20252

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.