Critical Splunk Flaw Lets Attackers Run Code
Splunk Enterprise has a critical unauthenticated flaw that hands attackers remote code execution.
CVE-2026-20253 scores CVSS 9.8. It lets unauthenticated users perform file operations that lead straight to code execution on the server.
Affects Splunk Enterprise deployments running vulnerable versions. Self-hosted instances without network restrictions are directly exposed.
WatchTowr published a technical breakdown two days after the June 10 advisory. No confirmed in-the-wild exploitation yet.
