CVE-2026-20253

Published Jun 10, 2026

Last updated 7 days ago

Exploit knownCVSS critical 9.8
Splunk
Network
Server
Database

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-20253 is a vulnerability affecting Splunk Enterprise and Splunk Cloud Platform, stemming from a lack of authentication controls in the PostgreSQL sidecar service endpoint. This flaw permits any network-reachable, unauthenticated user to perform file operations, specifically creating or truncating arbitrary files on the affected system. The vulnerability exists in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14. This unauthenticated file manipulation can potentially lead to unauthorized data tampering or disruption of service.

Description
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
Source
psirt@cisco.com
NVD status
Analyzed
Products
splunk

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Exploit added on
Jun 18, 2026
Exploit action due
Jun 21, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@cisco.com
CWE-306

Social media

Hype score
Not currently trending
  1. The speed at which new CVEs are going from PoC to mass exploitation has changed. In June alone we saw three CVEs: CVE-2026-10520, CVE-2026-20253, and CVE-2026-8451 being exploited in the wild less that 24 hours after a PoC became available for them. All of them have had https

    @LupovisDefence

    14 Jul 2026

    305 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    2 Quotes

  2. CVE-2026-20253: 🛡️ We added Splunk Enterprise missing authentication for critical function vulnerability CVE-2026-20253 to our KEV Catalog. Visit & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec…

    @lyrie_ai

    12 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 14:11 UTC: CVE-2026-20253 disclosed. CVE-2026-20253 Splunk Exploit Kit CVE-2026-20253 — Splunk Enterprise/Cloud PostgreSQL Sidecar Service Unauthenti 0day Intel: CVE-2026-20253 Splunk Exploit Kit CVE-2026-20253 — Splunk Enterprise/Cloud P

    @lyrie_ai

    10 Jul 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 19:29 UTC: CVE-2026-20253 disclosed. CVE-2026-20253 CVE-2026-20253 is a critical vulnerability (CVSS 9.8) in Splunk Enterprise and Splunk Cloud Platform. Su

    @lyrie_ai

    9 Jul 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. ⚠️ Vulnerabilidades en productos Splunk ❗ CVE-2026-20253 ❗ CVE-2026-20252 ❗ CVE-2026-20251 ➡️ Más info: https://t.co/YyA0IFRXsl https://t.co/Qr17pq0lUL

    @CERTpy

    3 Jul 2026

    207 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Top exploited KEVs we tracked over the past 7 days: 1 CVE-2025-61882 - Oracle EBS 2 CVE-2026-10520 - Ivanti Sentry 3 CVE-2022-47945 - ThinkPHP 4 CVE-2026-20230 - Cisco UCM 5 CVE-2026-46817 - Oracle EBS 6 CVE-2026-20253 - Splunk

    @kev_intel

    1 Jul 2026

    239 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🚨 CISA KEV Catalog Update June 2026 (status on 24.06.2026) - actively exploited vulnerabilities in the database: 🔹 Ubiquiti UniFi OS: CVE-2026-34908/34909/34910 (due 6/26) 🔹 Lantronix EDS5000: CVE-2025-67038 (due 6/26) 🔹 Splunk Enterprise: CVE-2026-20253 (due 6/21)

    @techepages

    24 Jun 2026

    104 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. For defenders, splunk enterprise cve-2026-20253 hits kev as exploitation begins should move fast. Splunk confirmed limited exploitation of CVE-2026-20253 and CISA added it to KEV. The flaw… 🔗 Details → https://t.co/iUwj6ykfgI

    @SocXAInvaders

    22 Jun 2026

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Legacy exposure keeps paying off for attackers. Splunk Enterprise CVE-2026-20253 hits KEV as exploitation… Splunk confirmed limited exploitation of CVE-2026-20253 and CISA added it to KEV. The flaw… 🔗 Read → https://t.co/ppQclsWHke

    @fynn_JourX

    22 Jun 2026

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Owning the right inbox can matter more than touching the whole network. Splunk confirmed limited exploitation of CVE-2026-20253 and CISA added it to KEV. 🔗 Details → https://t.co/xfJLLaBT0R

    @lucasverdan

    22 Jun 2026

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 🛑 Splunk Enterprise CVE-2026-20253 hits KEV as exploitation begins Splunk confirmed limited exploitation of CVE-2026-20253 and CISA added it to KEV. The flaw… 🔗 Details → https://t.co/xfJLLaBT0R

    @lucasverdan

    22 Jun 2026

    44 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. Splunk Enterpriseにおける認証不要のリモートコード実行(RCE)の脆弱性が現在攻撃を受けている(CVE-2026-20253) Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) #HelpNetSecurity (Jun 19) https://t.co/vRFgiz5qCn

    @foxbook

    22 Jun 2026

    232 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. CVE-2026-20253: Splunk Enterprise RCE Exploited CVE-2026-20253: CVSS 9.8 unauthenticated RCE in Splunk Enterprise. CISA added it to KEV June 18, 2026… Read more: https://t.co/a7TzprMk6X #Splunk #Cve202620253 #RemoteCodeExecution #Postgresql

    @navanem

    21 Jun 2026

    21 Impressions

    2 Retweets

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  14. Splunk CVE-2026-20253 wird aktiv ausgenutzt. Unauth RCE möglich. CISA setzt Frist bis 21. Juni für Behörden. Habt ihr bereits gepatcht? #CVE #Splunk #PatchManagement https://t.co/5ZzRvtMLiX

    @wall_your_x

    21 Jun 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CISO Daily Briefing: Splunk CVE-2026-20253 KEV remediation deadline is today; NGINX CVE-2026-42530/42055 (CVSS 9.2) and Chrome V8 CVE-2026-11645 zero-day both under active exploitation. OMB M-26-14 mandates federal logging posture change; U.S. restricts Anthropic's Fable 5/Mythos

    @cloudsa

    21 Jun 2026

    385 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) - Help Net Security https://t.co/bt9uPoY7Hx

    @PVynckier

    21 Jun 2026

    59 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🔒 #CyberSecurity CVE-2026-20253: Active Splunk Enterprise Exploitation — Emergency Patching & De… "CISA orders emergency patching of Splunk CVE-2026-20253 (Unauthenticated RCE) within 72…" 🔗 https://t.co/dTtcmGLns6 #CyberSecurity #ThreatIntel #cve #zeroday #pa

    @SecurityAr58409

    21 Jun 2026

    67 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 現状、#Fortigate にはSVD-2026-0603(CVE-2026-20253)のシグネチャないのか。本日時点での最新Sig、OSは8.0 https://t.co/s9ldvILyJ7

    @papa_anniekey

    20 Jun 2026

    1358 Impressions

    0 Retweets

    8 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE https://t.co/ZhLPT3WEYY CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE Introduction to Malware Binary Triage (IMBT) Course Looking to level up your skills? Get 10% off using coupon

    @f1tym1

    19 Jun 2026

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE https://t.co/ARmmfKCeTv CVE-2026-20253: CISA Warns of Actively Exploited Splunk Enterprise RCE Splunk Enterprise admins should prioritize patching CVE-2026-20253, a critical vulnerability that allows a net

    @f1tym1

    19 Jun 2026

    46 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253): CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal… https://t.co/54wST7N1Rs htt

    @shah_sheikh

    19 Jun 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Splunk has released security updates. The vulnerability, tracked as CVE-2026-20253 (CVSS score: 9.8) could be exploited to conduct unauthenticated file operations and even remote code execution. CISA has added it to KEV, giving federal agencies until June 21, 2026 to patch. http

    @ZeroDayFacts

    19 Jun 2026

    73 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 認証不要でSplunkサーバーを乗っ取れる深刻な脆弱性CVE-2026-20253のPoCが公開された。SplunkのPostgreSQLサイドカー機能を悪用し、ファイル作成からリモートコード実行まで可能になるため、SIEM基盤全体への侵害につ

    @yousukezan

    17 Jun 2026

    1615 Impressions

    1 Retweet

    5 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  24. How CVE-2026-20253 Turns Splunk’s PostgreSQL Sidecar Into an Open Door: CVE-2026-20253 is a CVSS 9.8 pre-auth flaw in Splunk Enterprise's PostgreSQL sidecar service. An unauthenticated attacker can write files and chain the primitive to RCE. A public PoC… https://t.co/a3MbIN3

    @shah_sheikh

    17 Jun 2026

    69 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. 🚨 CRITICAL: CVE-2026-20253 | CVSS 9.8 Splunk Enterprise & Cloud vulnerable to unauthenticated arbitrary file creation/truncation via PostgreSQL sidecar endpoint. Affected: <10.2.4, <10.0.7 (Enterprise) & <10.4.2604.3, <10.2.2510.14 (Cloud) #CVE #PatchNow

    @DFIR_Lab

    15 Jun 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. **CVE-2026-20253 Splunk Exploit Kit **CVE-2026-20253 — Splunk Enterprise/Cloud PostgreSQL Sidecar Service** **Unauthenticated Arbitrary File Creation/Truncation → Full RCE** **Military-Grade Multi-Stage Exploitation via pg_dump/pg_restore Chain** #exploit #0days #CVE #CVSS ht

    @YogSoth0

    15 Jun 2026

    889 Impressions

    1 Retweet

    22 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  27. 🚨 KEVIntel has observed active exploitation attempts for CVE-2026-20253 in our honeypots this morning. CVE-2026-20253 is a critical Splunk Enterprise vulnerability affecting the PostgreSQL sidecar service endpoint. What we observed: - First seen: 2026-06-15 05:15 UTC - 15 h

    @ethicalhack3r

    15 Jun 2026

    1183 Impressions

    2 Retweets

    1 Like

    2 Bookmarks

    0 Replies

    1 Quote

  28. 🚨 KEVIntel has observed active exploitation attempts for CVE-2026-20253 in our honeypots this morning. CVE-2026-20253 is a critical Splunk Enterprise vulnerability affecting the PostgreSQL sidecar service endpoint. What we observed: - First seen: 2026-06-15 05:15 UTC - 15 h

    @ethicalhack3r

    15 Jun 2026

    37 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  29. 🚨 CVE-2026-20253 - critical 🚨 Splunk Enterprise & Cloud Platform - Unrestricted File Upload > In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform vers... 👾 https://t.co/ruMSFh0Xvk @pdnuclei #NucleiTemplates #cve

    @pdnuclei_bot

    15 Jun 2026

    120 Impressions

    0 Retweets

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  30. CVE-2026-20253: Severe Splunk Vulnerability Puts Enterprise Servers at Risk #cybersecurity #cyashadotcom #WeSupportPeace https://t.co/2kB3FT91wr

    @cyashadotcom

    14 Jun 2026

    102 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  31. CVE-2026-20253: Splunk Pre-Auth RCE via PostgreSQL Sidecar https://t.co/8c6brLN8CR

    @thecybersecguru

    14 Jun 2026

    83 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  32. # CVE-2026-20253 Splunk Enterprise/Cloud PostgreSQL Sidecar Exploit Kit @UK_Daniel_Card it's coming 😉

    @YogSoth0

    14 Jun 2026

    281 Impressions

    0 Retweets

    5 Likes

    1 Bookmark

    1 Reply

    0 Quotes

  33. 🚨 “Security Tool is the Backdoor”: Inside Splunk’s CVSS 98 Nightmare (#CVE-2026-20253) https://t.co/pUn4YNMCp7 Educational Purposes!

    @UndercodeUpdate

    14 Jun 2026

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  34. 🔒 #CyberSecurity CVE-2026-20253: Critical Splunk Enterprise Unauthenticated RCE — Detection and … "Critical unauthenticated RCE (CVE-2026-20253) impacts Splunk Enterprise. Patch…" 🔗 https://t.co/2AxtlaAWjB #CyberSecurity #ThreatIntel #managedsoc #mdr #securitymoni

    @SecurityAr58409

    13 Jun 2026

    58 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  35. Splunk patched CVE-2026-20253, a critical 9.8 flaw that could let unauthenticated attackers write files and trigger remote code execution via PostgreSQL sidecar endpoints. #SplunkEnterprise #CVE-2026-20253 #WatchTowrLabs https://t.co/VABHuW6AQ0

    @TweetThreatNews

    13 Jun 2026

    171 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  36. Splunk just announced CVE-2026-20253 (CVSS 9.8) 🚨 The scary part? No authentication needed. An attacker can: > Hit the PostgreSQL sidecar endpoint > Write arbitrary files to your Splunk instance > Execute code with Splunk privileges Boom. RCE. @watchtowrcy

    @takkerohan97

    13 Jun 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  37. 🚨 Splunk, AWS i CVE Splunk ma krytyczną podatność CVE-2026-20253 z CVSS 9.8. I to nie w jakimś pobocznym dodatku, tylko w Splunk Enterprise, czyli narzędziu używanym do logów, monitoringu, observability i często także pracy zespołów security. Oficjalnie problem do

    @getriffsec

    13 Jun 2026

    280 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  38. Warning: Splunk has released multiple high and critical vulnerabilities in Splunk Enterprise. CVE-2026-20253 (CVSS 9.8) allows an unauthenticated attacker to create or truncate arbitrary files. CVE-2026-20251 (CVSS 8.8) could allow a low-privileged user to perform #RCE! #Patch

    @CCBalert

    11 Jun 2026

    197 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  39. Splunk Enterpriseで複数の脆弱性が修正された。最も深刻なCVE-2026-20253は認証不要で悪用可能な問題で、任意ファイルの作成や切り詰めを行えることから、システム侵害やデータ破壊につながる可能性がある。Splunk

    @yousukezan

    11 Jun 2026

    1511 Impressions

    1 Retweet

    10 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  40. A CVSS 9.8 flaw highlights new Splunk Enterprise vulnerabilities. Patch CVE-2026-20253, CVE-2026-20251, and others to prevent remote attacks on your servers. #Splunk #Cybersecurity #Vulnerability #CVE2026_20253 #InfoSec https://t.co/5541WMpWb5 https://t.co/QESmhwfDVE

    @Daily_CyberSec

    11 Jun 2026

    287 Impressions

    1 Retweet

    5 Likes

    1 Bookmark

    0 Replies

    0 Quotes

Configurations