{"id":11962,"date":"2026-09-21T12:35:28","date_gmt":"2026-09-21T18:35:28","guid":{"rendered":"https:\/\/beaconlab.us\/publicacion\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/"},"modified":"2026-09-29T10:59:08","modified_gmt":"2026-09-29T16:59:08","slug":"alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise","status":"publish","type":"publicacion","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/","title":{"rendered":"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">Affected product(s):<\/h2>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td><strong>Product<\/strong><\/td><td><strong>Affected versions<\/strong><\/td><td><strong>Fixed version<\/strong><\/td><\/tr><tr><td><strong>Splunk Enterprise<\/strong><\/td><td>10.0.0 to 10.0.6<\/td><td>10.0.7 or later<\/td><\/tr><tr><td><strong>Splunk Enterprise<\/strong><\/td><td>10.2.0 to 10.2.3<\/td><td>10.2.4 or later<\/td><\/tr><tr><td><strong>Splunk Enterprise<\/strong><\/td><td>10.4<\/td><td>Not affected<\/td><\/tr><tr><td><strong>Splunk Cloud Platform<\/strong><\/td><td>Not affected<\/td><td>Not applicable<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"has-small-font-size wp-block-paragraph\">*The vulnerability only affects Splunk Enterprise using the PostgreSQL <em>sidecar<\/em> component. <strong>Splunk Cloud Platform is not affected<\/strong>, since it does not use <em>Postgres sidecars<\/em>.<\/p>\n\n<h2 class=\"wp-block-heading\">Description<\/h2>\n\n<p class=\"wp-block-paragraph\">A vulnerability labeled <strong>CVE\u20112026\u201120253<\/strong> was identified, a critical vulnerability in <strong>Splunk Enterprise<\/strong> with a <strong>CVSS 9.8<\/strong> score. The flaw allows a remote unauthenticated attacker to perform arbitrary file operations through an exposed endpoint of the PostgreSQL <em>sidecar<\/em> service and, through an attack chain, achieve <strong>remote code execution (RCE)<\/strong> on the Splunk server.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>CVE\u20112026\u201120253<\/strong> occurs because the PostgreSQL <em>sidecar<\/em> service endpoint lacks authentication controls. Any actor able to reach the service over the network can invoke file operations without providing credentials.<a href=\"https:\/\/thehackernews.com\/2026\/06\/critical-splunk-enterprise-flaw-lets.html\" target=\"_blank\" rel=\"noopener\">thehackernews<\/a><\/p>\n\n<p class=\"wp-block-paragraph\">The vulnerability allows creating or truncating arbitrary files and can be chained to achieve pre-authentication RCE. The endpoints involved in the disclosed technical chain are:<\/p>\n\n<p class=\"wp-block-paragraph\">\/v1\/postgres\/recovery\/backup<br \/>\/v1\/postgres\/recovery\/restore<\/p>\n\n<p class=\"wp-block-paragraph\">The research team demonstrated that an attacker can use the \/backup endpoint to connect to a PostgreSQL database under their control and save a <em>dump<\/em> to an arbitrary path on the Splunk server&#8217;s file system. Subsequently, they can invoke \/restore, leveraging a local .pgpass file containing the postgres_admin account password, to restore attacker-controlled content into the local PostgreSQL instance.<\/p>\n\n<p class=\"wp-block-paragraph\">Although initially there were no reports of exploitation, the Splunk Product Security Incident Response Team (<strong>PSIRT<\/strong>) reported on June 18, 2026 that it had knowledge of <strong>limited exploitation<\/strong> of the vulnerability. CISA added CVE\u20112026\u201120253 to its Known Exploited Vulnerabilities (<strong>KEV<\/strong>) catalog, so immediate updating is recommended, along with reviewing potential indicators of compromise.<\/p>\n\n<h2 class=\"wp-block-heading\">Solution<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><strong>Update Splunk Enterprise immediately<\/strong> to a fixed version:<\/li>\n<\/ul>\n\n<ul class=\"wp-block-list\">\n<li>10.0.0\u201310.0.6 \u2192 update to <strong>10.0.7 or higher<\/strong>.<\/li>\n\n\n\n<li>10.2.0\u201310.2.3 \u2192 update to <strong>10.2.4 or higher<\/strong>.<\/li>\n\n\n\n<li>Splunk Enterprise 10.4 \u2192 not affected.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0603\">https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0603<\/a><\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/X\/Installation\/HowtoupgradeSplunk\">https:\/\/docs.splunk.com\/Documentation\/Splunk\/X\/Installation\/HowtoupgradeSplunk<\/a><\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/X\/Admin\/Serverconf\">https:\/\/docs.splunk.com\/Documentation\/Splunk\/X\/Admin\/Serverconf<\/a><\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/docs.splunk.com\/Documentation\/Splunk\/X\/Admin\/Postgresqlconf\">https:\/\/docs.splunk.com\/Documentation\/Splunk\/X\/Admin\/Postgresqlconf<\/a><\/p>\n\n<ul class=\"wp-block-list\">\n<li><strong>Identify all affected Splunk Enterprise instances<\/strong>, including <em>search heads<\/em>, <em>indexers<\/em>, management nodes, standalone servers, contingency environments, laboratories, and third-party deployments. Confirm whether each instance uses the PostgreSQL <em>sidecar<\/em>.<\/li>\n\n\n\n<li><strong>Restrict exposure of PostgreSQL sidecar endpoints and ports.<\/strong> Limit access to strictly authorized administrative networks and Splunk components; block any access from the Internet, user networks, guest segments, and non-administrative VPNs. This measure reduces exposure while patching is completed, but does not replace updating.<\/li>\n\n\n\n<li><strong>Review network, proxy, and Splunk logs<\/strong> to detect suspicious HTTP requests to:<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">\/v1\/postgres\/recovery\/backup<br \/>\/v1\/postgres\/recovery\/restore<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Investigate requests originating from unauthorized IPs, unplanned backup\/restore patterns, or anomalous responses.<\/li>\n\n\n\n<li><strong>Audit the integrity of critical Splunk files.<\/strong> Verify recent modifications, especially in application directories, Python scripts, configuration files, scheduled tasks, binaries, temporary directories, and paths associated with PostgreSQL recovery.<\/li>\n\n\n\n<li><strong>Search for persistence and post-compromise activity.<\/strong> Review unknown processes, anomalous outbound connections, new or modified credentials\/tokens, changes in administrative roles, <em>forwarder<\/em> configurations, alerts, <em>saved searches<\/em>, <em>lookups<\/em>, and installed applications.<\/li>\n\n\n\n<li><strong>Rotate secrets and credentials<\/strong> if indicators of compromise exist. Include Splunk administrative credentials, API tokens, deployment keys, integration secrets, certificates, database credentials, and service accounts used by <em>forwarders<\/em> or connectors.<\/li>\n<\/ul>\n\n<h2 class=\"wp-block-heading\">Additional information:<\/h2>\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/thehackernews.com\/2026\/06\/critical-splunk-enterprise-flaw-lets.html\">https:\/\/thehackernews.com\/2026\/06\/critical-splunk-enterprise-flaw-lets.html<\/a><\/li>\n\n\n\n<li>https:\/\/advisory.splunk.com\/advisories\/SVD-2026-0603<\/li>\n<\/ul>\n","protected":false},"featured_media":11421,"template":"","class_list":["post-11962","publicacion","type-publicacion","status-publish","has-post-thumbnail","hentry"],"acf":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Affected product(s): *The vulnerability only affects Splunk Enterprise using the PostgreSQL sidecar component. Splunk Cloud Platform is not affected, since it does not use Postgres sidecars. Description A vulnerability labeled CVE\u20112026\u201120253 was identified, a critical vulnerability in Splunk Enterprise with a CVSS 9.8 score. The flaw allows a remote unauthenticated attacker to perform arbitrary file\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Beacon Lab - CSIRT by Cybolt\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise - Beacon Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"Affected product(s): *The vulnerability only affects Splunk Enterprise using the PostgreSQL sidecar component. Splunk Cloud Platform is not affected, since it does not use Postgres sidecars. Description A vulnerability labeled CVE\u20112026\u201120253 was identified, a critical vulnerability in Splunk Enterprise with a CVSS 9.8 score. The flaw allows a remote unauthenticated attacker to perform arbitrary file\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/04\/Splunk.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/04\/Splunk.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"250\" \/>\n\t\t<meta property=\"og:image:height\" content=\"185\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-21T18:35:28+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-29T16:59:08+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@BeaconLabMX\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise - Beacon Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Affected product(s): *The vulnerability only affects Splunk Enterprise using the PostgreSQL sidecar component. Splunk Cloud Platform is not affected, since it does not use Postgres sidecars. Description A vulnerability labeled CVE\u20112026\u201120253 was identified, a critical vulnerability in Splunk Enterprise with a CVSS 9.8 score. The flaw allows a remote unauthenticated attacker to perform arbitrary file\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/04\/Splunk.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#listItem\",\"name\":\"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#listItem\",\"position\":2,\"name\":\"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#listItem\",\"name\":\"Home\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"telephone\":\"+528007374357\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.mx\\\/wp-content\\\/uploads\\\/2023\\\/12\\\/BeaconLab_V2-03.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/BeaconLabMX\",\"https:\\\/\\\/www.linkedin.com\\\/showcase\\\/beaconlabmx\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#webpage\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/\",\"name\":\"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise - Beacon Lab\",\"description\":\"Affected product(s): *The vulnerability only affects Splunk Enterprise using the PostgreSQL sidecar component. Splunk Cloud Platform is not affected, since it does not use Postgres sidecars. Description A vulnerability labeled CVE\\u20112026\\u201120253 was identified, a critical vulnerability in Splunk Enterprise with a CVSS 9.8 score. The flaw allows a remote unauthenticated attacker to perform arbitrary file\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#breadcrumblist\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/Splunk.png\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#mainImage\",\"width\":250,\"height\":185},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/publication\\\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\\\/#mainImage\"},\"datePublished\":\"2026-09-21T12:35:28-06:00\",\"dateModified\":\"2026-09-29T10:59:08-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/\",\"name\":\"Beacon Lab\",\"description\":\"CSIRT by Cybolt\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/beaconlab.us\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise - Beacon Lab","description":"Affected product(s): *The vulnerability only affects Splunk Enterprise using the PostgreSQL sidecar component. Splunk Cloud Platform is not affected, since it does not use Postgres sidecars. Description A vulnerability labeled CVE\u20112026\u201120253 was identified, a critical vulnerability in Splunk Enterprise with a CVSS 9.8 score. The flaw allows a remote unauthenticated attacker to perform arbitrary file","canonical_url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BreadcrumbList","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","position":1,"name":"Home","item":"https:\/\/beaconlab.us\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#listItem","name":"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise"}},{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#listItem","position":2,"name":"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise","previousItem":{"@type":"ListItem","@id":"https:\/\/beaconlab.us\/en\/#listItem","name":"Home"}}]},{"@type":"Organization","@id":"https:\/\/beaconlab.us\/en\/#organization","name":"Beacon Lab","description":"CSIRT by Cybolt","url":"https:\/\/beaconlab.us\/en\/","telephone":"+528007374357","logo":{"@type":"ImageObject","url":"https:\/\/beaconlab.mx\/wp-content\/uploads\/2023\/12\/BeaconLab_V2-03.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#organizationLogo"},"image":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#organizationLogo"},"sameAs":["https:\/\/twitter.com\/BeaconLabMX","https:\/\/www.linkedin.com\/showcase\/beaconlabmx"]},{"@type":"WebPage","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#webpage","url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/","name":"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise - Beacon Lab","description":"Affected product(s): *The vulnerability only affects Splunk Enterprise using the PostgreSQL sidecar component. Splunk Cloud Platform is not affected, since it does not use Postgres sidecars. Description A vulnerability labeled CVE\u20112026\u201120253 was identified, a critical vulnerability in Splunk Enterprise with a CVSS 9.8 score. The flaw allows a remote unauthenticated attacker to perform arbitrary file","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/beaconlab.us\/en\/#website"},"breadcrumb":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#breadcrumblist"},"image":{"@type":"ImageObject","url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/04\/Splunk.png","@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#mainImage","width":250,"height":185},"primaryImageOfPage":{"@id":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/#mainImage"},"datePublished":"2026-09-21T12:35:28-06:00","dateModified":"2026-09-29T10:59:08-06:00"},{"@type":"WebSite","@id":"https:\/\/beaconlab.us\/en\/#website","url":"https:\/\/beaconlab.us\/en\/","name":"Beacon Lab","description":"CSIRT by Cybolt","inLanguage":"en-US","publisher":{"@id":"https:\/\/beaconlab.us\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Beacon Lab - CSIRT by Cybolt","og:type":"article","og:title":"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise - Beacon Lab","og:description":"Affected product(s): *The vulnerability only affects Splunk Enterprise using the PostgreSQL sidecar component. Splunk Cloud Platform is not affected, since it does not use Postgres sidecars. Description A vulnerability labeled CVE\u20112026\u201120253 was identified, a critical vulnerability in Splunk Enterprise with a CVSS 9.8 score. The flaw allows a remote unauthenticated attacker to perform arbitrary file","og:url":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/","og:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/04\/Splunk.png","og:image:secure_url":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/04\/Splunk.png","og:image:width":250,"og:image:height":185,"article:published_time":"2026-09-21T18:35:28+00:00","article:modified_time":"2026-09-29T16:59:08+00:00","twitter:card":"summary_large_image","twitter:site":"@BeaconLabMX","twitter:title":"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise - Beacon Lab","twitter:description":"Affected product(s): *The vulnerability only affects Splunk Enterprise using the PostgreSQL sidecar component. Splunk Cloud Platform is not affected, since it does not use Postgres sidecars. Description A vulnerability labeled CVE\u20112026\u201120253 was identified, a critical vulnerability in Splunk Enterprise with a CVSS 9.8 score. The flaw allows a remote unauthenticated attacker to perform arbitrary file","twitter:image":"https:\/\/beaconlab.us\/wp-content\/uploads\/2026\/04\/Splunk.png"},"aioseo_meta_data":{"post_id":"11962","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"WebPage","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-29 16:58:15","updated":"2026-09-29 17:49:57","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/beaconlab.us\/en\/\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tAlert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/beaconlab.us\/en\/"},{"label":"Alert 2026-105 Pre-authenticated RCE Vulnerability in Splunk Enterprise","link":"https:\/\/beaconlab.us\/en\/publication\/alert-2026-105-pre-authenticated-rce-vulnerability-in-splunk-enterprise\/"}],"_links":{"self":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11962","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion"}],"about":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/types\/publicacion"}],"version-history":[{"count":1,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11962\/revisions"}],"predecessor-version":[{"id":11963,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/publicacion\/11962\/revisions\/11963"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media\/11421"}],"wp:attachment":[{"href":"https:\/\/beaconlab.us\/en\/wp-json\/wp\/v2\/media?parent=11962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}