Splunk Issues Urgent Fixes for RCE and Clear-Text Token Leaks
ID: 8e87e81b-ba04-575c-9fc0-9cee6981ab70
STIX ID: report--8e87e81b-ba04-575c-9fc0-9cee6981ab70
Feed Name: securityonline.info
Splunk published advisories for two serious vulnerabilities: CVE-2026-20204 allows a low-privileged user to upload a malicious file to $SPLUNK_HOME/var/run/splunk/apptemp and potentially achieve remote code execution on hosts with Splunk Web enabled, and CVE-2026-20205 in the Splunk MCP Server app can expose session and authorization tokens in clear text within internal logs. Administrators are urged to apply specified patches/updates (Splunk Enterprise, Splunk Cloud Platform, and MCP Server app), consider disabling Splunk Web as a temporary mitigation for the RCE issue, and restrict access to internal indexes to administrator-level roles.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
