news.mlab.sh
Back to the feed
vulnerability

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Critical
Image: The Hacker News
Summary

A critical vulnerability (CVE-2026-20253) has been identified in Splunk Enterprise versions below 10.2.4 and 10.0.7, allowing unauthenticated users to execute arbitrary code and potentially gain remote access. The flaw stems from a lack of authentication controls in the PostgreSQL sidecar service endpoint, and while no known exploitation has been reported, the availability of the exploit details poses a risk. Prompt patching is strongly advised to mitigate this threat.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.