CVE-2026-20253: In Splunk Enterprise versions below 10.2.4 and 10.0.7, and
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.
- CISA KEV-listed (remediation due 2026-06-21)
- EPSS 96.9% (99.9% percentile)
- CVSS 9.8 critical
Related briefings
- A shared Splunk report can leak an admin session 2026-08-20
- Critical vulnerabilities surged 62% in the second quarter of 2026 2026-07-07
- Hackers exploit Fortinet FortiSandbox flaws to hijack malware analysis servers 2026-06-22
- Critical Splunk bug lets attackers take over servers without a login 2026-06-14