← Back to Vulnerability Reports CVE Intelligence

CVE-2026-20253

Splunk EnterpriseCRITICAL · CVSS 9.8No exploitation reported

What is CVE-2026-20253?

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

CVSS9.8 NVD 3.1
SeverityCRITICAL
ExploitationNo exploitation reported
EPSS<1% · P21
Triage statusNo Known Exploit
ActionPatch within 48 hours
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWECWE-306
NVD published2026-06-10
NVD last modified2026-06-10

Affected product

Splunk Enterprise

Remediation Steps

  1. Upgrade Splunk Enterprise to version 10.2.4 or 10.0.7 or later
  2. If immediate upgrade is not possible, restrict network access to Splunk Enterprise instances to trusted internal networks only
  3. Review authentication and authorization logs for suspicious unauthenticated file operations
  4. Apply vendor security updates as soon as they become available
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.

Get Critical CVE Alerts

Subscribe free and hear about actively exploited CVEs like this one first.