Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution The vulnerability tracked as CVE202620253 is rated 98 on the CVSS scoring system In Splunk Enterprise versions below 1024 and 1007 an unauthenticated user could create or truncate arbitrary