CVE-2026-20253
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100º percentile).
Data di correzione federale CISA 21 giu
Vulnerabilità ed exploit
Un bug di Splunk che sembra un problema ristretto di scrittura su file diventa molto più ampio quando il sidecar vulnerabile è abilitato di default in Splunk Enterprise su AWS. In quella configurazione, un richiedente non autenticato può creare o troncare file arbitrari tramite un endpoint pubblico, quindi patchare solo l’app core non coglie il raggio d’azione dell’impatto.
1 fonte · 12 giu
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100º percentile).
Data di correzione federale CISA 21 giu
watchTowr Labs
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
On June 10th, Splunk published this CVE-2026-20253 advisory: It has everything that we love: * No authentication
originalePart of the PlainSec briefing for 2026-06-13
Every edition of this story: Default Splunk Sidecar Espone il Controllo dei File