PT-2026-48493 · Splunk · Splunk Enterprise+1
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Enterprise versions prior to 10.0.7
Splunk Enterprise versions prior to 10.2.4
Description
An unauthenticated user can create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. This occurs because the endpoint lacks authentication controls, allowing any network-reachable user to perform file operations without credentials. This flaw can be leveraged to achieve pre-authentication remote code execution with Splunk-level privileges. Approximately 1,400 instances of the software are exposed to the internet, primarily in North America and Europe, and there have been reports of limited exploitation in real-world attacks.
Recommendations
Update Splunk Enterprise to version 10.0.7.
Update Splunk Enterprise to version 10.2.4.
As a temporary workaround, disable the PostgreSQL sidecar service in the server configuration.
Exploit
Fix
LPE
RCE
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Cloud Platform
Splunk Enterprise