Cross-site scripting in Splunk Enterprise - CVE-2026-20258
Published: June 12, 2026
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote user to execute unauthorized JavaScript code in another user's browser.
The vulnerability exists due to cross-site scripting in the classic dashboard HTML panel when processing stored dashboard content. A remote user can store a malicious script and trick the victim into initiating a request within their browser to execute unauthorized JavaScript code in another user's browser.
User interaction is required, and exploitation requires the dashboard_html_allow_embeddable_content setting to be enabled.