logo

Splunk Issues Urgent Fixes for RCE and Clear-Text Token Leaks

ID: 8e87e81b-ba04-575c-9fc0-9cee6981ab70

STIX ID: report--8e87e81b-ba04-575c-9fc0-9cee6981ab70

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Ddos

...
...

Splunk published advisories for two serious vulnerabilities: CVE-2026-20204 allows a low-privileged user to upload a malicious file to $SPLUNK_HOME/var/run/splunk/apptemp and potentially achieve remote code execution on hosts with Splunk Web enabled, and CVE-2026-20205 in the Splunk MCP Server app can expose session and authorization tokens in clear text within internal logs. Administrators are urged to apply specified patches/updates (Splunk Enterprise, Splunk Cloud Platform, and MCP Server app), consider disabling Splunk Web as a temporary mitigation for the RCE issue, and restrict access to internal indexes to administrator-level roles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.