Splunk Patches CVE-2026-20253, a 9.8-Rated Unauthenticated RCE in Enterprise

The advisory covers Splunk Enterprise builds below 10.2.4 and 10.0.7, with fixed versions now available.

ThreatVectr Newsdesk· 2 min read
Splunk Patches CVE-2026-20253, a 9.8-Rated Unauthenticated RCE in Enterprise
Share

Splunk has issued fixes for a critical vulnerability in Splunk Enterprise that permits unauthenticated file operations and, under the right conditions, remote code execution.

The flaw is tracked as CVE-2026-20253. It carries a CVSS v3.1 base score of 9.8.

Per the vendor advisory, the bug affects Splunk Enterprise versions below 10.2.4 and 10.0.7. An unauthenticated user can create or truncate arbitrary files on the host running the Splunk instance. That primitive — arbitrary file write without credentials — is what pushes the severity into the critical band and opens the door to code execution.

The fix is a version bump. Administrators should upgrade to 10.2.4, 10.0.7, or later on the maintained branches.

A few things worth flagging for compliance and disclosure teams.

First, the CVSS 9.8 rating matters beyond optics. Under the SEC's cyber disclosure rule adopted in July 2023 (Item 1.05 of Form 8-K), a registrant must assess whether an incident exploiting a flaw of this class is material and, if so, file within four business days of that determination. The rule governs incidents, not unpatched CVEs — but a Splunk deployment sitting inside the security stack of a public company changes the materiality calculus quickly if exploitation occurs.

Second, U.S. federal civilian agencies should watch CISA's Known Exploited Vulnerabilities catalog. Inclusion in the KEV triggers Binding Operational Directive 22-01 remediation deadlines, typically two weeks for critical entries. CVE-2026-20253 was not on the KEV at the time of writing. That status can change without warning if in-the-wild exploitation is observed.

Third, EU operators caught by NIS2 should treat this as a significant incident candidate if exploitation is detected. Article 23 requires an early warning to the relevant CSIRT within 24 hours of awareness, an incident notification within 72 hours, and a final report within one month. The clock starts at awareness, not at confirmation of impact.

Splunk has not, as of publication, indicated active exploitation. The advisory does not credit an external researcher in the materials reviewed, suggesting internal discovery — though that is not confirmed.

Mitigation guidance from the vendor is upgrade-first. There is no documented configuration workaround in the advisory text. Operators running Splunk Cloud Platform should confirm with their account team which maintenance window applies; on-prem operators control their own timeline.

Review SIEM and EDR telemetry for unexpected file creation or truncation events on Splunk indexer and search head hosts. Anomalous writes outside standard index and bucket paths warrant investigation.

Patch, then audit.

© 2026 Threat Vectr