FeedCritical Splunk Enterprise Flaw Lets Attackers Run Code With...
The Hacker News

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

📅 13 June 2026 at 13:23 UTC📰 The Hacker NewsView original source ↗
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution. The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system. "In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary

Read the full article

This is a curated summary. The complete article is available at The Hacker News.

Read on The Hacker News
← Back to feed