Vulnerability intelligence
CVE-2026-20253
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
CVSS Score
9.8
Critical
EPSS — Exploit Probability
96%
Riskier than 100% of all CVEs
Exploitation
Confirmed in the wild
KEV since 2026-06-18
Remediation
Patch available
Federal deadline 2026-06-21
8 articles across 6 outlets · first covered Jun 11, 2026 · latest Jun 19, 2026
Tracked incidents
Coverage timeline
-
CVE-2026-20253 Splunk bug lets hackers run code remotelysocradar.io · Jun 19, 2026
-
CISA adds Splunk flaw CVE-2026-20253, urges patch by June 21securityaffairs.com · Jun 19, 2026
-
Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosurewww.securityweek.com · Jun 19, 2026
-
CISA Adds Splunk Auth Bypass Flaw to KEV Catalog, Urging Patcheswww.cisa.gov · Jun 18, 2026
-
CISA flags critical Splunk flaw enabling unauthenticated file editscisa.gov · Jun 18, 2026
-
Splunk CVE-2026-20253: CVSS 9.8 RCE Exploited in the Wildsecurityonline.info · Jun 18, 2026
-
Palo Alto fixes Cortex flaw: Splunk patches Enterprise bugwww.securityweek.com · Jun 11, 2026
-
Check Point VPN under attack as Splunk issues urgent patchessecurityonline.info · Jun 11, 2026