PT-2026-48493 · Splunk · Splunk Enterprise+1

·

CVE-2026-20253

·

Published

2026-06-10

·

Updated

2026-09-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk Enterprise versions prior to 10.0.7 Splunk Enterprise versions prior to 10.2.4
Description An unauthenticated user can create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. This occurs because the endpoint lacks authentication controls, allowing any network-reachable user to perform file operations without credentials. This flaw can be leveraged to achieve pre-authentication remote code execution with Splunk-level privileges. Approximately 1,400 instances of the software are exposed to the internet, primarily in North America and Europe, and there have been reports of limited exploitation in real-world attacks.
Recommendations Update Splunk Enterprise to version 10.0.7. Update Splunk Enterprise to version 10.2.4. As a temporary workaround, disable the PostgreSQL sidecar service in the server configuration.

Exploit

Fix

LPE

RCE

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20253

Affected Products

Splunk Cloud Platform
Splunk Enterprise