Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Severity : Critical (CVE-2026-20253)

CVSS v3.1 Score : 9.8

*

Information

   Splunk Enterprise is a widely used enterprise-grade log management and data analytics platform developed by Splunk Inc. It serves as a centralized solution for collecting, indexing, searching, monitoring, and analyzing machine-generated data from various sources, including servers, network devices, firewalls, applications, databases, and cloud services. The platform enables organizations to gain real-time visibility into their IT infrastructure, detect security threats, troubleshoot operational issues, and generate actionable insights through powerful search, reporting, dashboard, and alerting capabilities. Splunk Enterprise is widely used for log management, security monitoring, IT operations, and business analytics across organizations of all sizes.

Incident

  CVE-2026-20253 is a critical security vulnerability affecting Splunk Enterprise. The flaw resides in a PostgreSQL sidecar service that fails to properly enforce authentication, allowing remote attackers to perform arbitrary file operations without valid credentials. Due to its low attack complexity and the absence of authentication requirements, the vulnerability poses a significant risk to organizations relying on Splunk for security monitoring, log management, and operational visibility.

 

  Security researchers have demonstrated that the vulnerability can be leveraged beyond simple file creation or truncation, potentially enabling Remote Code Execution (RCE) and full compromise of the affected Splunk server. A successful attack could allow adversaries to tamper with security logs, disrupt monitoring capabilities, establish persistence, and use the compromised system as a foothold for further attacks within the enterprise network.

 

  At the time of disclosure, there were no widespread reports of active exploitation in the wild; however, due to the public availability of technical details and proof-of-concept research, organizations should assume that exploitation attempts may increase rapidly and take immediate remediation actions.

Affected Products and Versions

  • Splunk Enterprise versions below 10.2.4 and 10.0.7

Recommendation

  • Upgrade to the following patched versions immediately:

oSplunk Enterprise 10.4.0, 10.2.4, 10.0.7, 9.4.12, or 9.3.13

oSplunk Cloud Platform 10.4.2604.3, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, or 9.3.2411.132 (depending on release track)

oSplunk Secure Gateway app 3.10.6, 3.9.20, or 3.8.67

  • Where immediate patching is not possible:

oDisabling or removing the Splunk Secure Gateway app mitigates CVE-2026-20251 (note: this impacts Splunk Mobile, Spacebridge, and Mission Control functionality)

oDisabling Splunk Web where feasible reduces the XSS and SSRF attack surface

 

The important things is Security systems. We must concern and monitor as usual.
For more information please contact
Email :sales@inetms.co.th
065 149 2822 (Ms.Suphatson )
063 204 4534 (Ms.Atsamaphorn)
065 929 6330 (Ms.Kansinee)
092 257 6902 (Ms.Narusorn)
063 197 7510 (Mr.Yanotai)
065 725 7405 (Ms.Nattharini)
065 725 7405 (Ms.Donraya)

 

References

Weekly Interesting CVE

NO.

CVE Name

Published Date

Last Update

Device/Appplication/OS Target

Attack Type

CVSS
Severity Rating

Detail

Solution

Reference

1

CVE-2026-20245

4/6/2026

5/6/2026

Cisco Catalyst SD-WAN Manager

Zero - day

7.8

A vulnerability has been discovered in the Command-Line Interface, stemming from insufficient validation of user-supplied input. An attacker could exploit this system by uploading a specially crafted file to the affected system. If successful, this would allow the attacker to execute arbitrary commands on the operating system, enabling them to escalate their privileges to root.

No vendor fix or workaround currently provided.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW

 

 

2

CVE-2026-48567

4/6/2026

5/6/2026

Microsoft Azure HorizonDB

Authentication Bypass by Spoofing

10

A vulnerability has been discovered that allows an unauthenticated attacker to exploit the system over the network, bypass authentication mechanisms, and escalate their privileges on the database without requiring credentials. An attacker can access, modify, or delete critical data within the Azure HorizonDB database with maximum privileges.

Apply the latest security patches.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-48567

3

CVE-2026-21031

5/6/2026

6/6/2026

Samsung Mobile Android 15/16

Improper Authorization

7.8

A vulnerability has been discovered due to a flaw in the validation and authorization process within the operating system's AppBlock component. A local attacker could exploit this vulnerability to launch activities or applications that should normally be restricted. If successful, the application can bypass the block and execute commands that may lead to the unauthorized access of sensitive local information. However, it cannot cause a system crash or overwrite deep-level system data.

Apply the latest security patches.

https://security.samsungmobile.com/securityUpdate.smsb?year=2026&month=06

 4

CVE-2026-0006

26/5/2026

3/6/2026

Mirasvit Full Page Cache Warmer version 1.11.12

PHP Object Injection

9.8

A vulnerability has been discovered arising from a flaw in how the extension handles data via PHP's unserialize() function. An external, unauthenticated attacker can exploit the system by crafting a payload, embedding it into an HTTP Cookie named CacheWarmer, and sending it to the target server. When the server processes the forged object, it allows the attacker to execute arbitrary PHP code and commands on the server. This means the attacker could completely take over the online storefront system, access the database to steal customers' personal information, or use the compromised system to further distribute malware.

Update to version 1.11.12 or later to resolve the vulnerability.

https://www.vulncheck.com/advisories/mirasvit-cache-warmer-for-magento-php-object-injection

5

CVE-2026-6735

10/5/2026

12/5/2026

PHP version 8.2

Cross-Site Scripting (XSS)

7.3

A vulnerability has been discovered arising from insufficient input sanitization on the PHP-FPM Status Page, specifically concerning the Request URI variable. An attacker can exploit this vulnerability by crafting a malicious link or URL embedded with harmful JavaScript code. If an administrator inadvertently clicks or is tricked into visiting the Status Page via this link, the JavaScript code will execute immediately within the victim's browser as a Reflected Cross-Site Scripting (XSS) attack. Although this vulnerability does not allow an attacker to take over the server or execute operating system commands directly (No RCE), a successful XSS attack could lead to the theft of session cookies or sensitive data stored in the browser.

Update to version 8.2.31, 8.3.31 or later to resolve the vulnerability.

https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv

 

Malware News or Campaign IOC/IOA | EN

No

Campaign Name

Detection Date

Attack

Type

 

Description

 

Mitigation/Remediation

1

New malspam campaign uses Google DoubleClick to deliver DesckVB RAT

04/06/2026

Malware

Researchers from Huntress discovered a new malware campaign leveraging Google's DoubleClick domain as an intermediary to evade detection. The attack begins with a phishing email containing an HTML attachment. Once opened, the victim is redirected through a Google DoubleClick URL to a spoofed landing page that displays the target company's branding and details to appear more convincing. Clicking a "Download PDF" button triggers the download of a ZIP file containing a JavaScript loader, which uses a technique called Process Hollowing to inject a .NET malware into legitimate Windows processes.

The malware used in this campaign is the DesckVB RAT, first observed in February 2026. It carries a wide range of capabilities including data theft, remote command execution, and downloading additional payloads. It also disables security mechanisms such as AMSI and ETW, and can detect sandbox environments to evade analysis. Security experts recommend that organizations configure DMARC, DKIM, and SPF records, and deploy an Email Gateway solution capable of sandboxing attachments and links to defend against this type of threat.

  • Avoid downloading files or executing commands from untrusted sources.
  • Keep systems and applications up to date
  • Strengthen user security awareness

Ref: https://thehackernews.com/2026/06/weekly-recap-new-linux-flaw-pan-os.html

16 June 2026

Viewed 85 time

Engine by shopup.com