logo

Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks

ID: 2c57211b-402e-5638-8029-f288974d2bb7

STIX ID: report--2c57211b-402e-5638-8029-f288974d2bb7

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-04-16

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical RCE vulnerability (CVE-2026-20204, CVSS 7.1) in Splunk Enterprise and Cloud's Splunk Web component (CWE-377) enables low-privileged users to gain remote code execution by uploading crafted files to `SPLUNK_HOME/var/run/splunk/apptemp`. The advisory lists affected release branches, recommends immediate patching or temporarily disabling the Splunk Web interface, and notes Splunk has seen no active exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.