What is CVE-2026-20253?
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
Timeline
- 2026-06-10Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-14First covered in a defend.network daily briefing
- 2026-06-18Added to the CISA Known Exploited Vulnerabilities (KEV) catalog
- 2026-06-19NVD record last updated
- 2026-06-21CISA federal remediation deadline (BOD 22-01)
CISA Known Exploited Vulnerability
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Affected product
Splunk Enterprise
Remediation Steps
- Apply the vendor patch for Splunk Enterprise Missing Authentication issue immediately
- Verify patch installation across all Splunk Enterprise instances
- Monitor Splunk logs for any evidence of unauthorized access or exploitation attempts
- Restrict network access to Splunk management interfaces to trusted networks only
References
- https://advisory.splunk.com/advisories/SVD-2026-0603
- https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20253
- https://nvd.nist.gov/vuln/detail/CVE-2026-20253
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 2 of July 2026 (July 13 – 19)
- Vulnerability Priority Report – Week 1 of July 2026 (July 6 – 12)
- Vulnerability Priority Report – Week 5 of June 2026 (June 29 – July 5)
- Vulnerability Priority Report – Week 4 of June 2026 (June 22 – 28)
- Vulnerability Priority Report – Week 3 of June 2026 (June 15 – 21)
- Vulnerability Priority Report – Week 2 of June 2026 (June 8 – 14)
- Critical: Splunk RCE, Arch Linux supply-chain hijack, phishing-as-a-service dismantled (2026-06-15)
- Splunk RCE, Arch Linux supply-chain hijack, Velvet Ant decade-long backdoor (2026-06-14)
Browse all tracked CVEs in the defend.network CVE database →