
Splunk Enterprise Flaws Enable Credential Theft, Path Traversal, and SPL Abuse
Splunk has released patches for three vulnerabilities affecting Splunk Enterprise and Splunk Cloud Platform, including a high-severity CSRF flaw in Deployment Server and a path traversal bug in the app installation workflow. The most severe issue, tracked as CVE-2026-20296, carries a CVSSv3.1 score of 8.3 and stems from the absence of CSRF token validation on […]
The post Splunk Enterprise Flaws Enable Credential Theft, Path Traversal, and SPL Abuse appeared first on Cyber Security News.