CVE-2026-20253
Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise
Description
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
In plain language
AI Act nowCVE-2026-20253 is a critical Splunk Enterprise bug that lets an internet attacker, without logging in, create or wipe arbitrary files via a PostgreSQL sidecar endpoint—if you run Splunk Enterprise 10.2.x below 10.2.4 or 10.x below 10.0.7 with that sidecar enabled, you should act immediately.
CVE-2026-20253 is an unauthenticated arbitrary file creation and truncation issue in Splunk Enterprise caused by missing authentication controls on a PostgreSQL sidecar service endpoint; affected versions (Splunk Enterprise 10.2.x < 10.2.4 and Splunk Enterprise/ Splunk 10.x < 10.0.7) can be remotely triggered without user interaction when the endpoint is network-reachable.
What to do now
- Check your Splunk Enterprise version and whether the PostgreSQL sidecar service is enabled and reachable from the network.
- Confirm the system is exposed to untrusted networks (for example, internet reachability) on the PostgreSQL sidecar endpoint.
- Upgrade Splunk Enterprise to 10.2.4 or later if you are on the 10.2.x branch.
- Upgrade Splunk Enterprise (or Splunk) to 10.0.7 or later if you are on the 10.0–10.1 branch.
- If you cannot upgrade immediately, disable the PostgreSQL sidecar service per Splunk guidance and restrict network access to the endpoint.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- 22nd June – Threat Intelligence Reporten-us·Check Point Research· Roundup Fortinet FortiSandbox Icarus
- ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and Moreen·The Hacker News· Roundup Fortinet FortiGate Icarus
- 2,060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)en-us·Daily CyberSecurity (securityonline.info)· Exploited Splunk Enterprise zero-day
- CISA: Splunk Enterprise flaw actively exploited, patch by Sundayen-us·BleepingComputer· Exploited Splunk Enterprise rce
- Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosureen-us·SecurityWeek· Exploited Splunk Enterprise rce
- Splunk CVE-2026-20253: CVSS 9.8 RCE Exploited in the Wilden-us·Daily CyberSecurity (securityonline.info)· Exploited Splunk Enterprise rce
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and Moreen·The Hacker News· Exploited Chrome (V8) UNC6240 (ShinyHunters)
- Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authenticationen·The Hacker News· Patch Splunk Enterprise 10.0.7 rce
- Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)en·watchTowr Labs· Research Splunk Enterprise rce
- Splunk, Palo Alto Networks Patch Severe Vulnerabilitiesen-us·SecurityWeek· Patch Splunk Enterprise rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20253 and every CVE in our database. Create a free account — no credit card required.
Create Free Account