
Splunk Enterprise's open sidecar: the unauthenticated 9.8 that turns your SIEM into a foothold (CVE-2026-20253)
CVE-2026-20253 is an unauthenticated arbitrary file-write in a PostgreSQL sidecar service that Splunk Enterprise 10.x ships alongside Edge Processor, OpAmp and SPL2 pipelines. It scores CVSS 9.8, sits at the 99.87th EPSS percentile, and is on CISA KEV with limited in-the-wild exploitation confirmed. Here's the missing-auth root cause, the exact affected versions, and how to patch — or disable the sidecar — without losing features.


















