PatchSiren cyber security CVE debrief
CVE-2026-20252 Splunk CVE debrief
A vulnerability was discovered in Splunk Enterprise and Splunk Cloud Platform. A low-privileged user that does not hold the 'admin' or 'power' Splunk roles could send server-side requests to arbitrary internal destinations through the Dashboard Studio PDF export feature. The vulnerability exists due to trusted-domain validation using a prefix match that can be bypassed with attacker-controlled subdomains and because the PDF export service follows HTTP redirects automatically without re-validating each redirect target against the allowlist.
- Vendor
- Splunk
- Product
- Splunk Enterprise
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-10
- Original CVE updated
- 2026-06-15
- Advisory published
- 2026-06-10
- Advisory updated
- 2026-06-15
Who should care
Users of Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132 should apply the necessary patches to prevent exploitation.
Technical summary
The vulnerability is caused by a prefix match in the trusted-domain validation and the automatic following of HTTP redirects by the PDF export service without re-validation. This allows a low-privileged user to send server-side requests to arbitrary internal destinations.
Defensive priority
HIGH
Recommended defensive actions
- Apply patches for Splunk Enterprise versions: 10.2.4, 10.0.7, 9.4.12, and 9.3.13
- Apply patches for Splunk Cloud Platform versions: 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132
- Restrict access to the Dashboard Studio PDF export feature to only trusted users
Evidence notes
The CVE-2026-20252 vulnerability was identified in Splunk Enterprise and Splunk Cloud Platform. The vulnerability allows a low-privileged user to send server-side requests to arbitrary internal destinations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-20252 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-20252
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-20252 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-20252
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-0602
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.