Skip to content
The Nexus
SECURITYJun 13 · 13:23 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has released security updates to address a critical flaw in Splunk Enterprise, allowing unauthenticated users to perform file operations and execute remote code. The vulnerability, CVE-2026-20253, has a CVSS score of 9.8 and affects versions below 10.2.4 and 10.0.7.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting