Splunk Enterprise and Cloud Platform Vulnerability Enables Remote Code Execution Attacks
ID: 2c57211b-402e-5638-8029-f288974d2bb7
STIX ID: report--2c57211b-402e-5638-8029-f288974d2bb7
Feed Name: cybersecurityNews.com
Threat Score
A critical RCE vulnerability (CVE-2026-20204, CVSS 7.1) in Splunk Enterprise and Cloud's Splunk Web component (CWE-377) enables low-privileged users to gain remote code execution by uploading crafted files to `SPLUNK_HOME/var/run/splunk/apptemp`. The advisory lists affected release branches, recommends immediate patching or temporarily disabling the Splunk Web interface, and notes Splunk has seen no active exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
