Cybersecurity

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

AU
Published June 13, 2026
1 min read 1 views
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution.

The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system.

"In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary

Original report published on: https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html