← Vulnerability feed

Vulnerability record · CVE-2026-20253 · published 10 June 2026

CVE-2026-20253: Splunk Enterprise PostgreSQL sidecar missing authentication allows file writes

Splunk · Splunk

Splunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any network-reachable user can invoke file operations without credentials, creating or truncating arbitrary files. Versions 9.4 and earlier are not affected.

9.8 CVSS 3.1 Critical CISA KEV since 18 Jun 2026 EPSS 97% · top 0.1% CWE-306 · Missing authentication for critical function
9.8CVSS 3.1 base score
97%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References, 1 tagged exploit
23 Jul 2026Last modified by NVD

Description

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, KEV-listed with a three-day federal remediation deadline, and EPSS near 0.97 make this an urgent patch.

What it is

Splunk Enterprise 10.2 below 10.2.4 and 10.x below 10.0.7 expose a PostgreSQL sidecar service endpoint that lacks authentication controls. Any network-reachable user can invoke file operations without credentials, creating or truncating arbitrary files. Versions 9.4 and earlier are not affected.

Impact

An unauthenticated attacker can create or truncate arbitrary files on the host, which can corrupt data or enable further compromise such as code execution depending on what files are writable. The CVSS vector rates confidentiality, integrity and availability all High.

Attack surface

Reached over the network via the PostgreSQL sidecar service endpoint; the CVSS vector is AV:N/AC:L/PR:N/UI:N, so no authentication and no user interaction are required. Any host that can reach the exposed endpoint qualifies as an attack path.

Exploitation

CISA added it to KEV on 2026-06-18 with a remediation due date of 2026-06-21, and EPSS gives a 30-day probability of 0.96939 (99.887th percentile). A third-party advisory is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Splunk Enterprise to 10.2.4 or later, or 10.0.7 or later, per the vendor advisory SVD-2026-0603.
  • If immediate upgrade is not possible, disable the PostgreSQL sidecar service as the vendor directs.
  • Restrict network access to the PostgreSQL sidecar endpoint so only trusted hosts can reach it.
  • Treat any internet-exposed Splunk Enterprise instance as compromised until triaged, given KEV listing and high EPSS.
  • Verify no unauthorized files were created or truncated on affected hosts before restoring service.

Detection

  • Audit file creation and truncation events on Splunk Enterprise hosts for paths outside normal Splunk write activity.
  • Monitor network connections to the PostgreSQL sidecar service port from unexpected or external sources.
  • Review Splunk Enterprise and PostgreSQL sidecar logs for unauthenticated requests to file operation endpoints.
  • Check for unexpected changes to configuration or binary files that could indicate tampering.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-20253 to the Known Exploited Vulnerabilities catalog on 18 June 2026 as "Splunk Enterprise Missing Authentication for Critical Function Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 21 June 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20253 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2022-32158Splunk improper access control vulnerabilitySplunk Enterprise deployment servers in versions before 8.1.10.1, 8.2.6.1, and 9.0 let clients deploy forwarder bundles to other deployment clients t…EPSS 1.4%9.8CVE-2022-37437Splunk improper certificate validation vulnerabilityWhen using Ingest Actions to configure a destination that resides on Amazon Simple Storage Service (S3) in Splunk Web, TLS certificate validation is …EPSS 0.44%9.8CVE-2017-17067Splunk incorrect authorization vulnerabilitySplunk Web in Splunk Enterprise 7.0.x before 7.0.0.1, 6.6.x before 6.6.3.2, 6.5.x before 6.5.6, 6.4.x before 6.4.9, and 6.3.x before 6.3.12, when the…EPSS 3.0%9.8CVE-2016-10126Splunk permissions and access controls vulnerabilitySplunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x bef…EPSS 4.0%9.4CVE-2026-76310Splunk improper access control vulnerabilityIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the a…EPSS 0.45%9.4CVE-2026-76311Splunk improper access control vulnerabilityIn Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the d…EPSS 0.45%9.4CVE-2026-76312Splunk improper access control vulnerabilityIn Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) sou…EPSS 0.45%

Source: NIST National Vulnerability Database (record CVE-2026-20253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.