Splunk Enterprise RCE via Unauthenticated File Operations: Pre-Authentication Compromise of Widely-Deployed Log Analytics Platform
CVE-2026-20253, a CVSS 9.8 critical vulnerability in Splunk Enterprise versions before 10.2.4 and 10.0.7, permits unauthenticated attackers to perform arbitrary file operations and achieve remote code execution, affecting a primary target for enterprise threat actors seeking post-compromise persistence and reconnaissance.