CVE-2021-26253: Bypass of Splunk Enterprise's implementation of DUO MFA
A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing the MFA verification in Splunk Enterprise versions before 8.1.6. The potential vulnerability impacts Splunk Enterprise instances configured to use DUO MFA and does not impact or affect a DUO product or service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26253?
The severity of CVE-2021-26253 is considered high due to its potential to bypass multi-factor authentication in Splunk Enterprise versions before 8.1.6.
How do I fix CVE-2021-26253?
To fix CVE-2021-26253, upgrade your Splunk Enterprise to version 8.1.6 or later.
Who is affected by CVE-2021-26253?
CVE-2021-26253 affects Splunk Enterprise instances that are configured to use DUO MFA and are running versions prior to 8.1.6.
What functionalities does CVE-2021-26253 impact?
CVE-2021-26253 impacts the multi-factor authentication mechanism within Splunk Enterprise when using DUO MFA.
Is there a workaround for CVE-2021-26253?
Currently, there is no documented workaround for CVE-2021-26253, so upgrading to the fixed version is recommended.