Splunk RCE Vulnerability Allows Attackers to Execute Arbitrary Shell Commands
A critical security advisory has been issued regarding a high-severity vulnerability affecting both Enterprise and Cloud platforms. Identified as CVE-2026-20163, this flaw has a CVSS score of 8.0, enabling attackers to perform Remote Command Execution…
A critical security advisory has been issued regarding a high-severity vulnerability affecting both Enterprise and Cloud platforms. Identified as CVE-2026-20163, this flaw has a CVSS score of 8.0, enabling attackers to perform Remote Command Execution (RCE) on targeted systems.
The vulnerability arises from improper handling of user inputs when previewing uploaded files before indexing. Although the exploit requires high-level privileges, successful exploitation could allow a malicious user to gain control of the host server.
The core issue is classified under CWE-77, involving the improper neutralization of special elements used in a command. The vulnerability is located within the REST API component of Splunk, specifically targeting the /splunkd/__upload/indexing/preview endpoint.
To exploit this flaw, an attacker must have a user role that includes the high-privilege edit_cmd capability. If this condition is met, the attacker can manipulate the unarchive_cmd parameter during the file upload preview process. Due to improper input sanitization, the attacker can inject and execute arbitrary shell commands on the server.
This security flaw was responsibly disclosed by security researcher Danylo Dmytriiev (DDV_UA), along with Splunk internal team members Gabriel Nitu and James Ervin.
A critical security advisory has been issued regarding a high-severity vulnerability affecting both Enterprise and Cloud platforms.
The vulnerability affects several recent versions of Splunk's software. Administrators should verify their deployments against the following affected releases:
Enterprise 10.0.0–10.0.3, 9.4.0–9.4.8, 9.3.0–9.3.9 Cloud Platform versions below 10.2.2510.5, 10.1.2507.16, 10.0.2503.12, and 9.3.2411.124
The base Splunk Enterprise 10.2 release is not affected by this vulnerability. Splunk is actively monitoring and deploying patches directly to affected Cloud Platform instances.
To safeguard infrastructure, Splunk strongly recommends addressing this vulnerability immediately through updates or temporary mitigations.
Upgrade Splunk Enterprise: Administrators should update to fixed versions 10.2.0, 10.0.4, 9.4.9, 9.3.10, or higher. Implement Workarounds: If an immediate upgrade is not possible, remove the high-privilege edit_cmd capability from all user roles to mitigate risk. This breaks the exploit chain by denying permissions required for malicious command execution.
Currently, no specific threat detection signatures are available for this vulnerability. Hence, proactive patching and strict privilege management are crucial.
Based on reporting by Cyber Security News.
