Back to overview

CVE-2026-20253

CRITICAL KEV CISA Exploitation: ACTIVE
9.8
CVSS 3.1
Description
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.

Metadata

CVE ID
CVE-2026-20253
State
PUBLISHED
Assigner
cisco
Reserved
2025-10-08 11:59 UTC
Published
2026-06-10 17:16 UTC
Last updated
2026-06-19 03:55 UTC
Primary CWE
CWE-306
The software does not perform any authentication for functio…
Vendor / Product
Splunk / Splunk Enterprise
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Vendor
Splunk
Product
Enterprise
Added to KEV
2026-06-18
Due date
2026-06-21
Ransomware
Not known
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA description
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
Affected products (1)
VendorProductPlatformVersions
Splunk Splunk Enterprise 10.2 < 10.2.4, 10.0 < 10.0.7
Weakness (CWE)
CWESourceDescription
CWE-306 cna The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview