securityonline.info 6/18/2026, 7:02:27 PM · external

Splunk CVE-2026-20253: CVSS 9.8 RCE Exploited in the Wild

Splunk CVE-2026-20253: CVSS 9.8 RCE Exploited in the Wild
Developing story vulnerability 3 articles tracked
Splunk Enterprise critical vulnerabilities (including CVE-2026-20253) exploited in the wild
CyberSIXT Evidence Panel
Primary Source cisa.gov
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THE page discusses a critical vulnerability in Splunk Enterprise, identified as CVE-2026-20253, which allows for remote code execution due to insufficient authentication controls in the PostgreSQL sidecar service. The CVSS score is 9.8, and it affects versions below 10.2.4 and 10.0.7. CISA has confirmed active exploitation in the wild, urging immediate updates to the patched versions.

The flaw enables unauthorized file operations, leading to potential administrative credential exposure and system compromise through an SQL attack chain. Organizations are advised to update their software or temporarily disable the affected service. Federal agencies have a remediation deadline of June 21, 2026.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline