CVE-2026-20253
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100º percentile).
Data di correzione federale CISA 21 giu
Vulnerabilità · 109 giorni fa
Un bug di Splunk che sembra un problema ristretto di scrittura su file diventa molto più ampio quando il sidecar vulnerabile è abilitato di default in Splunk Enterprise su AWS. In quella configurazione, un richiedente non autenticato può creare o troncare file arbitrari tramite un endpoint pubblico, quindi patchare solo l’app core non coglie il raggio d’azione dell’impatto.
Sfruttamento noto · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100º percentile).
Data di correzione federale CISA 21 giu
1 fonte che coprono questa storia
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
On June 10th, Splunk published this CVE-2026-20253 advisory: It has everything that we love: * No authentication
Part of the PlainSec briefing for 2026-06-13