Splunk Enterprise Vulnerabilities: Patch CVSS 9.8 Flaws
ID: 86579928-b20a-5c6c-9a16-83a2ad6b7df6
STIX ID: report--86579928-b20a-5c6c-9a16-83a2ad6b7df6
Feed Name: securityonline.info
**Executive Summary:** Multiple critical vulnerabilities in Splunk Enterprise are disclosed, including an unauthenticated arbitrary file creation/truncation bug (CVE-2026-20253, CVSS 9.8), an RCE via unsafe deserialization in the Splunk Secure Gateway (CVE-2026-20251, CVSS 8.8), a stored XSS in the classic dashboard (CVE-2026-20258, CVSS 7.1), and an SSRF via Dashboard Studio PDF export (CVE-2026-20252, CVSS 7.6); administrators are urged to apply vendor patches to supported versions (10.4.0, 10.2.4, 10.0.7, 9.4.12, 9.3.13) or implement recommended temporary mitigations (disable Splunk Web or the Secure Gateway app) immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
