In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4...
Moderate severity
Unreviewed
Published
Jun 10, 2026
to the GitHub Advisory Database
•
Updated Jun 10, 2026
Description
Published by the National Vulnerability Database
Jun 10, 2026
Published to the GitHub Advisory Database
Jun 10, 2026
Last updated
Jun 10, 2026
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that does not hold the 'admin' or 'power' Splunk roles could cause data exfiltration through classic dashboards by redirecting a victim to an external site using a protocol-relative URL in a drill-down link.
The vulnerability exists because the URL classifier in classic dashboards only recognizes
http://andhttps://schemes when checking for external URLs. Protocol-relative URLs such as//attacker.combypass this check entirely, and Splunk Web does not show the external-navigation warning dialog to the victim.References