Vulnerabilities · 87 days ago

Splunk’s Control Plane Is Now the Target

A Splunk server is not just another app when it sits in the monitoring path. If an attacker reaches this flaw, they can do more than run code on one box: they can interfere with security visibility, tamper with logs, and pull stored credentials from the platform that other teams trust to tell them what is happening.

CVE-2026-20253 affects Splunk Enterprise 10.2 before 10.2.4 and 10.0 before 10.0.7, with Splunk Cloud fixes at 10.4.2604.3 and 10.2.2510.14. The bug is in the PostgreSQL sidecar service endpoint, which lacks authentication and lets a network-reachable caller invoke file operations; public PoC followed quickly, Splunk confirmed limited in-the-wild exploitation, and CISA put it in KEV with a June 21 deadline for federal agencies.

That turns patching into a visibility problem as much as a code-execution problem. An attacker who owns Splunk can hide follow-on activity and use what the platform stores to move deeper into the environment.

CVE-2026-20253

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100th percentile).

CISA federal remediation date Jun 21

Timeline

Sources

4 sources covering this story

Entities

Part of the PlainSec briefing for 2026-06-14

Editions