Sale of a 1-day exploit for Splunk Enterprise with Pre-Auth RCE
Dark Web2026-06-29, 12:53
For informational purposes only
Affected versions: Splunk Enterprise 10.2 below 10.2.4 and version 10 below 10.0.7
Type of vulnerability: Pre-Auth RCE
Price: $5 million
The seller claims to be selling a 1-day exploit for Splunk Enterprise CVE-2026-20253. The vulnerability allows an unauthenticated user to create arbitrary files through the PostgreSQL sidecar service endpoint without needing to have credentials.
According to the author, the problem affects Splunk Enterprise 10.2 up to version 10.2.4, as well as version 10 up to version 10.0.7. The vulnerability is declared as critical, with a CVSS v3.1 rating of 9.8.
A public research PoC/detector from watchTowr Labs has already been published for the vulnerability.
Splunk Enterprise is a corporate platform for collecting, indexing, and analyzing machine data, used in logging, monitoring, observability, and SIEM scenarios. Splunk is one of the largest players in this segment: according to IDC, Splunk has been ranked first among SIEM suppliers for five consecutive years, Gartner in 2025 included Splunk in the Magic Quadrant for SIEM for the eleventh time, and 6sense estimates Splunk's share in the SIEM category at approximately 45.9% and in the log management category at approximately 8.4%. The scale of implementation is also significant: before the deal with Cisco, the company reported an ARR of $4.2 billion, and Reuters, citing Morningstar, noted that more than 90% of Fortune 100 companies use Splunk solutions; in March 2024, Cisco completed the purchase of Splunk for $28 billion.
Vulnerabilities
Researchers
Vendors
More
Products