Vulnerabilities · 109 days ago

Default Splunk Sidecar Exposes File Control

A Splunk bug that looks like a narrow file-write issue becomes much wider when the vulnerable sidecar is enabled by default in Splunk Enterprise on AWS. In that setup, an unauthenticated requester can create or truncate arbitrary files through a public endpoint, so patching the core app alone does not capture the blast radius.

WatchTowr says the flaw sits in the PostgreSQL Sidecar Service Endpoint and affects Splunk Enterprise and Splunk Cloud Platform versions called out in the advisory, with Splunk Enterprise on AWS shipping the service installed and enabled by default. That makes some deployments exposed out of the box and puts logs, configs, and other platform files at risk on systems many teams rely on for detection and monitoring.

CVE-2026-20253

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100th percentile).

CISA federal remediation date Jun 21

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-06-13

Editions

Related stories