Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3165 articles · 162184 vulns · 38/41 feeds (7d)
← Back to list
5.7
CVE-2026-20255EXPLOITEDPATCHED
splunk · splunk enterpri

Improper Input Validation through Classic Dashboards in Splunk Enterprise

Description

A vulnerability was found in Splunk Enterprise and Cloud Platform. It has been classified as problematic. Impacted is an unknown function. Performing a manipulation results in information disclosure. The attack can be initiated remotely.

Affected Products

VendorProductVersions
splunksplunk enterpri10.2, 10.0, 9.4, 9.3, 10.3.2512, 10.2.2510, 10.1.2507, 9.3.2411

References

  • https://advisory.splunk.com/advisories/SVD-2026-0605

Related News (1 articles)

Tier C
VulDB2h ago
CVE-2026-20255 | Splunk Enterprise/Cloud Platform information disclosure (SVD-2026-0605)
→ No new info (linked only)
CVSS 3.15.7 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
10.2.410.0.79.4.129.3.1310.3.2512.1310.2.2510.1510.1.2507.239.3.2411.132
CWECWE-20
PublishedJun 10, 2026
Last enriched2h agov2
Tags
information disclosure
Trending Score48
Source articles2
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20251EXP
Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway
Trending: 67
CRITICALCVE-2026-20259EXP
Improper Access Control in Splunk Enterprise
Trending: 51
CRITICALCVE-2026-20252EXP
Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise
Trending: 51
CRITICALCVE-2026-20254EXP
Information Disclosure through External Content Restriction Bypass in Splunk Enterprise
Trending: 51
HIGHCVE-2026-20257EXP
Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise
Trending: 48

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 10, 2026
Discovered by ZDM
Jun 10, 2026
Actively Exploited
Jun 10, 2026
Patch Available
Jun 10, 2026
Updated: description, severity, activelyExploited, tags
Jun 10, 2026

Version History

v2
Last enriched 2h ago
v2Tier C2h ago

Updated description with new details, changed severity to HIGH, and noted that the vulnerability is actively exploited.

descriptionseverityactivelyExploitedtags
via VulDB
v14h ago

Initial creation