【漏洞預警】Splunk Enterprise、Splunk Cloud Platform 及 Splunk Secure Gateway 存在高風險安全漏洞(CVE-2026-20251),請儘速確認並進行修補
內容說明
研究人員發現 Splunk Enterprise、Splunk Cloud Platform 及 Splunk Secure Gateway 存在不安全反序列化 (Insecure Deserialization)漏洞 CVE-2026-20251 。 已通過身分鑑別的遠端攻擊者,可透過對未受信任的資料進行反序列化, 進而在受影響的伺服器上執行任意程式碼。請儘速確認並進行修補。
影響平台
- Splunk Enterprise 10.2.0 至 10.2.3 版本
- Splunk Enterprise 10.0.0 至 10.0.6 版本
- Splunk Enterprise 9.4.0 至 9.4.11 版本
- Splunk Enterprise 9.3.0 至 9.3.12 版本
- Splunk Cloud Platform 10.3.2512.12 以前版本(不含該版本)
- Splunk Cloud Platform 10.2.2510.14 以前版本(不含該版本)
- Splunk Cloud Platform 10.1.2507.22 以前版本(不含該版本)
- Splunk Cloud Platform 9.3.2411.132 以前版本(不含該版本)
- Splunk Secure Gateway 3.10.6 以前版本(不含該版本)
- Splunk Secure Gateway 3.9.20 以前版本(不含該版本)
- Splunk Secure Gateway 3.8.67 以前版本(不含該版本)
建議措施
官方已針對此漏洞釋出修復更新,請參考 Splunk 官方安全公告 SVD-2026-0601 進行更新。

