External Publication
Visit Post

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

The Hacker News | #1 Trusted Source for Cybersecurity News [Uno… June 13, 2026
Source
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. "In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary

Discussion in the ATmosphere

Loading comments...