Splunk Sidecar Turns Internal Trust Into RCE

A network-reachable support service inside Splunk Enterprise can be used without logging in, so a component meant to stay behind the curtain becomes an unauthenticated path to code execution on the host. Patch-only thinking misses the real break: the attack surface is the internal recovery sidecar itself, not the main app UI. Splunk fixed CVE-2026-20253 in 10.0.7 and 10.2.4. It affects Splunk Enterprise 10.0.0 to 10.0.6 and 10.2.0 to 10.2.3; Splunk Cloud is not affected. watchTowr also published working details showing the flaw can be chained through backup and restore functions to reach pre-authenticated remote code execution. This raises the bar above a routine hardening note. The trust boundary inside the product is the failure point, so single-host scoping and “monitoring tool only” assumptions do not hold.

Part of the PlainSec briefing for 2026-06-14

Sources