CVE-2026-20253
Published Jun 10, 2026
Last updated 7 days ago
AI description
CVE-2026-20253 is a vulnerability affecting Splunk Enterprise and Splunk Cloud Platform, stemming from a lack of authentication controls in the PostgreSQL sidecar service endpoint. This flaw permits any network-reachable, unauthenticated user to perform file operations, specifically creating or truncating arbitrary files on the affected system. The vulnerability exists in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14. This unauthenticated file manipulation can potentially lead to unauthorized data tampering or disruption of service.
- Description
- In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
- Source
- psirt@cisco.com
- NVD status
- Analyzed
- Products
- splunk
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Splunk Enterprise Missing Authentication for Critical Function Vulnerability
- Exploit added on
- Jun 18, 2026
- Exploit action due
- Jun 21, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- psirt@cisco.com
- CWE-306
- Hype score
- Not currently trending
The speed at which new CVEs are going from PoC to mass exploitation has changed. In June alone we saw three CVEs: CVE-2026-10520, CVE-2026-20253, and CVE-2026-8451 being exploited in the wild less that 24 hours after a PoC became available for them. All of them have had https
@LupovisDefence
14 Jul 2026
305 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
2 Quotes
CVE-2026-20253: 🛡️ We added Splunk Enterprise missing authentication for critical function vulnerability CVE-2026-20253 to our KEV Catalog. Visit & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec…
@lyrie_ai
12 Jul 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
14:11 UTC: CVE-2026-20253 disclosed. CVE-2026-20253 Splunk Exploit Kit CVE-2026-20253 — Splunk Enterprise/Cloud PostgreSQL Sidecar Service Unauthenti 0day Intel: CVE-2026-20253 Splunk Exploit Kit CVE-2026-20253 — Splunk Enterprise/Cloud P
@lyrie_ai
10 Jul 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
19:29 UTC: CVE-2026-20253 disclosed. CVE-2026-20253 CVE-2026-20253 is a critical vulnerability (CVSS 9.8) in Splunk Enterprise and Splunk Cloud Platform. Su
@lyrie_ai
9 Jul 2026
68 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ Vulnerabilidades en productos Splunk ❗ CVE-2026-20253 ❗ CVE-2026-20252 ❗ CVE-2026-20251 ➡️ Más info: https://t.co/YyA0IFRXsl https://t.co/Qr17pq0lUL
@CERTpy
3 Jul 2026
207 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Top exploited KEVs we tracked over the past 7 days: 1 CVE-2025-61882 - Oracle EBS 2 CVE-2026-10520 - Ivanti Sentry 3 CVE-2022-47945 - ThinkPHP 4 CVE-2026-20230 - Cisco UCM 5 CVE-2026-46817 - Oracle EBS 6 CVE-2026-20253 - Splunk
@kev_intel
1 Jul 2026
239 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA KEV Catalog Update June 2026 (status on 24.06.2026) - actively exploited vulnerabilities in the database: 🔹 Ubiquiti UniFi OS: CVE-2026-34908/34909/34910 (due 6/26) 🔹 Lantronix EDS5000: CVE-2025-67038 (due 6/26) 🔹 Splunk Enterprise: CVE-2026-20253 (due 6/21)
@techepages
24 Jun 2026
104 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
For defenders, splunk enterprise cve-2026-20253 hits kev as exploitation begins should move fast. Splunk confirmed limited exploitation of CVE-2026-20253 and CISA added it to KEV. The flaw… 🔗 Details → https://t.co/iUwj6ykfgI
@SocXAInvaders
22 Jun 2026
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Legacy exposure keeps paying off for attackers. Splunk Enterprise CVE-2026-20253 hits KEV as exploitation… Splunk confirmed limited exploitation of CVE-2026-20253 and CISA added it to KEV. The flaw… 🔗 Read → https://t.co/ppQclsWHke
@fynn_JourX
22 Jun 2026
25 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Owning the right inbox can matter more than touching the whole network. Splunk confirmed limited exploitation of CVE-2026-20253 and CISA added it to KEV. 🔗 Details → https://t.co/xfJLLaBT0R
@lucasverdan
22 Jun 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 Splunk Enterprise CVE-2026-20253 hits KEV as exploitation begins Splunk confirmed limited exploitation of CVE-2026-20253 and CISA added it to KEV. The flaw… 🔗 Details → https://t.co/xfJLLaBT0R
@lucasverdan
22 Jun 2026
44 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Splunk Enterpriseにおける認証不要のリモートコード実行(RCE)の脆弱性が現在攻撃を受けている(CVE-2026-20253) Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) #HelpNetSecurity (Jun 19) https://t.co/vRFgiz5qCn
@foxbook
22 Jun 2026
232 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-20253: Splunk Enterprise RCE Exploited CVE-2026-20253: CVSS 9.8 unauthenticated RCE in Splunk Enterprise. CISA added it to KEV June 18, 2026… Read more: https://t.co/a7TzprMk6X #Splunk #Cve202620253 #RemoteCodeExecution #Postgresql
@navanem
21 Jun 2026
21 Impressions
2 Retweets
5 Likes
1 Bookmark
0 Replies
0 Quotes
Splunk CVE-2026-20253 wird aktiv ausgenutzt. Unauth RCE möglich. CISA setzt Frist bis 21. Juni für Behörden. Habt ihr bereits gepatcht? #CVE #Splunk #PatchManagement https://t.co/5ZzRvtMLiX
@wall_your_x
21 Jun 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISO Daily Briefing: Splunk CVE-2026-20253 KEV remediation deadline is today; NGINX CVE-2026-42530/42055 (CVSS 9.2) and Chrome V8 CVE-2026-11645 zero-day both under active exploitation. OMB M-26-14 mandates federal logging posture change; U.S. restricts Anthropic's Fable 5/Mythos
@cloudsa
21 Jun 2026
385 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) - Help Net Security https://t.co/bt9uPoY7Hx
@PVynckier
21 Jun 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-20253: Active Splunk Enterprise Exploitation — Emergency Patching & De… "CISA orders emergency patching of Splunk CVE-2026-20253 (Unauthenticated RCE) within 72…" 🔗 https://t.co/dTtcmGLns6 #CyberSecurity #ThreatIntel #cve #zeroday #pa
@SecurityAr58409
21 Jun 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
現状、#Fortigate にはSVD-2026-0603(CVE-2026-20253)のシグネチャないのか。本日時点での最新Sig、OSは8.0 https://t.co/s9ldvILyJ7
@papa_anniekey
20 Jun 2026
1358 Impressions
0 Retweets
8 Likes
0 Bookmarks
1 Reply
0 Quotes
CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE https://t.co/ZhLPT3WEYY CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon
@f1tym1
19 Jun 2026
46 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE https://t.co/ARmmfKCeTv CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE Splunk Enterprise admins should prioritize patching CVE-2026-20253, a critical vulnerability that allows a net
@f1tym1
19 Jun 2026
46 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253): CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal… https://t.co/54wST7N1Rs htt
@shah_sheikh
19 Jun 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Splunk has released security updates. The vulnerability, tracked as CVE-2026-20253 (CVSS score: 9.8) could be exploited to conduct unauthenticated file operations and even remote code execution. CISA has added it to KEV, giving federal agencies until June 21, 2026 to patch. http
@ZeroDayFacts
19 Jun 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
認証不要でSplunkサーバーを乗っ取れる深刻な脆弱性CVE-2026-20253のPoCが公開された。SplunkのPostgreSQLサイドカー機能を悪用し、ファイル作成からリモートコード実行まで可能になるため、SIEM基盤全体への侵害につ
@yousukezan
17 Jun 2026
1615 Impressions
1 Retweet
5 Likes
4 Bookmarks
0 Replies
0 Quotes
How CVE-2026-20253 Turns Splunk’s PostgreSQL Sidecar Into an Open Door: CVE-2026-20253 is a CVSS 9.8 pre-auth flaw in Splunk Enterprise's PostgreSQL sidecar service. An unauthenticated attacker can write files and chain the primitive to RCE. A public PoC… https://t.co/a3MbIN3
@shah_sheikh
17 Jun 2026
69 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-20253 | CVSS 9.8 Splunk Enterprise & Cloud vulnerable to unauthenticated arbitrary file creation/truncation via PostgreSQL sidecar endpoint. Affected: <10.2.4, <10.0.7 (Enterprise) & <10.4.2604.3, <10.2.2510.14 (Cloud) #CVE #PatchNow
@DFIR_Lab
15 Jun 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
**CVE-2026-20253 Splunk Exploit Kit **CVE-2026-20253 — Splunk Enterprise/Cloud PostgreSQL Sidecar Service** **Unauthenticated Arbitrary File Creation/Truncation → Full RCE** **Military-Grade Multi-Stage Exploitation via pg_dump/pg_restore Chain** #exploit #0days #CVE #CVSS ht
@YogSoth0
15 Jun 2026
889 Impressions
1 Retweet
22 Likes
5 Bookmarks
0 Replies
0 Quotes
🚨 KEVIntel has observed active exploitation attempts for CVE-2026-20253 in our honeypots this morning. CVE-2026-20253 is a critical Splunk Enterprise vulnerability affecting the PostgreSQL sidecar service endpoint. What we observed: - First seen: 2026-06-15 05:15 UTC - 15 h
@ethicalhack3r
15 Jun 2026
1183 Impressions
2 Retweets
1 Like
2 Bookmarks
0 Replies
1 Quote
🚨 KEVIntel has observed active exploitation attempts for CVE-2026-20253 in our honeypots this morning. CVE-2026-20253 is a critical Splunk Enterprise vulnerability affecting the PostgreSQL sidecar service endpoint. What we observed: - First seen: 2026-06-15 05:15 UTC - 15 h
@ethicalhack3r
15 Jun 2026
37 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-20253 - critical 🚨 Splunk Enterprise & Cloud Platform - Unrestricted File Upload > In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform vers... 👾 https://t.co/ruMSFh0Xvk @pdnuclei #NucleiTemplates #cve
@pdnuclei_bot
15 Jun 2026
120 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
CVE-2026-20253: Severe Splunk Vulnerability Puts Enterprise Servers at Risk #cybersecurity #cyashadotcom #WeSupportPeace https://t.co/2kB3FT91wr
@cyashadotcom
14 Jun 2026
102 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-20253: Splunk Pre-Auth RCE via PostgreSQL Sidecar https://t.co/8c6brLN8CR
@thecybersecguru
14 Jun 2026
83 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
# CVE-2026-20253 Splunk Enterprise/Cloud PostgreSQL Sidecar Exploit Kit @UK_Daniel_Card it's coming 😉
@YogSoth0
14 Jun 2026
281 Impressions
0 Retweets
5 Likes
1 Bookmark
1 Reply
0 Quotes
🚨 “Security Tool is the Backdoor”: Inside Splunk’s CVSS 98 Nightmare (#CVE-2026-20253) https://t.co/pUn4YNMCp7 Educational Purposes!
@UndercodeUpdate
14 Jun 2026
42 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-20253: Critical Splunk Enterprise Unauthenticated RCE — Detection and … "Critical unauthenticated RCE (CVE-2026-20253) impacts Splunk Enterprise. Patch…" 🔗 https://t.co/2AxtlaAWjB #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymoni
@SecurityAr58409
13 Jun 2026
58 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Splunk patched CVE-2026-20253, a critical 9.8 flaw that could let unauthenticated attackers write files and trigger remote code execution via PostgreSQL sidecar endpoints. #SplunkEnterprise #CVE-2026-20253 #WatchTowrLabs https://t.co/VABHuW6AQ0
@TweetThreatNews
13 Jun 2026
171 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
Splunk just announced CVE-2026-20253 (CVSS 9.8) 🚨 The scary part? No authentication needed. An attacker can: > Hit the PostgreSQL sidecar endpoint > Write arbitrary files to your Splunk instance > Execute code with Splunk privileges Boom. RCE. @watchtowrcy
@takkerohan97
13 Jun 2026
86 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Splunk, AWS i CVE Splunk ma krytyczną podatność CVE-2026-20253 z CVSS 9.8. I to nie w jakimś pobocznym dodatku, tylko w Splunk Enterprise, czyli narzędziu używanym do logów, monitoringu, observability i często także pracy zespołów security. Oficjalnie problem do
@getriffsec
13 Jun 2026
280 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Warning: Splunk has released multiple high and critical vulnerabilities in Splunk Enterprise. CVE-2026-20253 (CVSS 9.8) allows an unauthenticated attacker to create or truncate arbitrary files. CVE-2026-20251 (CVSS 8.8) could allow a low-privileged user to perform #RCE! #Patch
@CCBalert
11 Jun 2026
197 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Splunk Enterpriseで複数の脆弱性が修正された。最も深刻なCVE-2026-20253は認証不要で悪用可能な問題で、任意ファイルの作成や切り詰めを行えることから、システム侵害やデータ破壊につながる可能性がある。Splunk
@yousukezan
11 Jun 2026
1511 Impressions
1 Retweet
10 Likes
5 Bookmarks
0 Replies
0 Quotes
A CVSS 9.8 flaw highlights new Splunk Enterprise vulnerabilities. Patch CVE-2026-20253, CVE-2026-20251, and others to prevent remote attacks on your servers. #Splunk #Cybersecurity #Vulnerability #CVE2026_20253 #InfoSec https://t.co/5541WMpWb5 https://t.co/QESmhwfDVE
@Daily_CyberSec
11 Jun 2026
287 Impressions
1 Retweet
5 Likes
1 Bookmark
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "0C9F1DED-280E-4C76-A867-A7A8FCBD1F7A",
"versionEndExcluding": "10.0.7",
"versionStartIncluding": "10.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "E3B992C0-AD5E-43A1-BAA3-6B11FFD5D750",
"versionEndExcluding": "10.2.4",
"versionStartIncluding": "10.2.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]