Critical severity9.8CISA KEVNVD Advisory· Published Jun 10, 2026· Updated Jun 16, 2026
CVE-2026-20253
CVE-2026-20253
Description
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: >=10.0, <10.0.7 or >=10.2, <10.2.4
Patches
Vulnerability mechanics
References
2News mentions
15- 22nd June – Threat Intelligence ReportCheck Point Research · Jul 1, 2026
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and MoreThe Hacker News · Jun 22, 2026
- Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attackHelp Net Security · Jun 21, 2026
- Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)Help Net Security · Jun 19, 2026
- CISA: Splunk Enterprise flaw actively exploited, patch by SundayBleepingComputer · Jun 19, 2026
- CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in AttacksCyber Security News · Jun 19, 2026
- Splunk Enterprise Vulnerability Exploited in Attacks Days After DisclosureSecurityWeek · Jun 19, 2026
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News · Jun 15, 2026
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without AuthenticationThe Hacker News · Jun 13, 2026
- Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero AuthenticationCyber Security News · Jun 13, 2026
- Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)watchTowr Labs · Jun 12, 2026
- Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious ScriptCyber Security News · Jun 11, 2026
- Splunk, Palo Alto Networks Patch Severe VulnerabilitiesSecurityWeek · Jun 11, 2026
- Splunk: Critical and High Severity Vulnerabilities Disclosed Together on June 10, 2026Vypr Intelligence · Jun 10, 2026
- CISA Adds One Known Exploited Vulnerability to CatalogCISA Alerts