Input validation error in Splunk Enterprise - CVE-2026-20256
Published: June 12, 2026
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in classic dashboards when processing protocol-relative URLs in drill-down links. A remote user can create a crafted drill-down link to disclose sensitive information.
User interaction is required to follow the crafted link, and the external-navigation warning dialog is not shown.