All incidents

CISA adds Splunk Enterprise authentication bypass flaw (CVE-2026-20253) to KEV catalog

vulnerabilityclosedJun 11, 2026 — Jun 19, 2026
CISA adds Splunk Enterprise authentication bypass flaw (CVE-2026-20253) to KEV catalog

CISA has added CVE-2026-20253 to its Known Exploited Vulnerabilities catalog after confirming active exploitation of a critical authentication bypass in Splunk Enterprise the agency announced. The flaw lets unauthenticated attackers manipulate files on vulnerable systems and can lead to remote code execution. Affected releases include Splunk Enterprise 10.0.0 to 10.0.6 and 10.2.0 to 10.2.3.

The vulnerability resides in the PostgreSQL sidecar service endpoint which lacks proper authentication checks according to Splunk’s advisory. With a CVSS v3.1 base score of 9.8 it permits arbitrary file operations such as creating or truncating files that can be chained to execute code. Patches are available in versions 10.0.7 and 10.2.4.

Splunk confirmed that exploitation was observed in the wild on June 18 just days after the June 10 patch release SecurityWeek reported. Attackers can send crafted requests to the exposed sidecar service to alter files on the underlying host. This file manipulation can facilitate further privilege escalation or deployment of malicious payloads.

Although no specific threat actor has been linked to the activity CISA's addition to the KEV catalogue indicates that the flaw is being actively used the agency's alert notes. Federal agencies have been directed to apply mitigations by June 21 2026 while private organisations are urged to prioritize patching. The entry in the KEV catalogue serves as a formal indicator of ongoing risk.

Defenders should first upgrade to the patched releases 10.0.7 or 10.2.4 as soon as possible Security Affairs advises. If immediate upgrading is not feasible the PostgreSQL sidecar service can be disabled temporarily to block the attack vector. Network segmentation should restrict lateral movement from untrusted zones to the Splunk management interface.

Administrators are also encouraged to monitor logs for unexpected file creation or deletion events and to review the NVD entry for detailed mitigations the NVD page provides. Maintaining current backups and testing patches in a non‑production environment will reduce the chance of disruption during remediation. Following these steps will help close the gap before attackers can expand their foothold.

Intelligence briefing updated Jun 19, 2026

CVE-2026-20253 9.8 KEV CVE-2026-50751 9.3 KEV CVE-2026-20251 8.8 CVE-2026-0274 8.1 CVE-2026-20252 7.6 CVE-2026-20258 7.1
Root sourceadvisory.splunk.com
Timeline Coverage

Swipe to explore timeline