CVE-2026-20253

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) En las versiones de Splunk Enterprise 10.2 anteriores a la 10.2.4 y las versiones 10 anteriores a la 10.0.7, un usuario no autenticado podría crear o truncar archivos arbitrarios a través de un endpoint del servicio sidecar de PostgreSQL. La vulnerabilidad existe porque el endpoint del servicio sidecar de PostgreSQL carece de controles de autenticación, lo que permite a cualquier usuario accesible por red invocar operaciones de archivo sin credenciales. Las versiones de Splunk Enterprise 9.4 y anteriores no se ven afectadas. Si no puede actualizar inmediatamente a una versión corregida, puede mitigar esta vulnerabilidad deshabilitando el servicio sidecar de PostgreSQL.

19 Jun 2026, 06:17

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20253 - US Government Resource
References () https://advisory.splunk.com/advisories/SVD-2026-0603 - Vendor Advisory () https://advisory.splunk.com/advisories/SVD-2026-0603 - Mitigation, Vendor Advisory
References () https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/ - () https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/ - Exploit, Third Party Advisory

16 Jun 2026, 15:16

Type Values Removed Values Added
References
  • () https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/ -

15 Jun 2026, 22:16

Type Values Removed Values Added
Summary (en) In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. (en) In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.

15 Jun 2026, 21:16

Type Values Removed Values Added
Summary (en) In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. (en) In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

15 Jun 2026, 15:22

Type Values Removed Values Added
CPE cpe:2.3:a:splunk:splunk:*:*:*:*:enterprise:*:*:*
First Time Splunk splunk
Splunk
References () https://advisory.splunk.com/advisories/SVD-2026-0603 - () https://advisory.splunk.com/advisories/SVD-2026-0603 - Vendor Advisory

10 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 18:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-20253

Mitre link : CVE-2026-20253

CVE.ORG link : CVE-2026-20253


JSON object : View

Products Affected

splunk

  • splunk
CWE
CWE-306

Missing Authentication for Critical Function