CVE-2026-20253
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100th percentile).
CISA federal remediation date Jun 21
Vulnerabilities · 109 days ago
A Splunk bug that looks like a narrow file-write issue becomes much wider when the vulnerable sidecar is enabled by default in Splunk Enterprise on AWS. In that setup, an unauthenticated requester can create or truncate arbitrary files through a public endpoint, so patching the core app alone does not capture the blast radius.
WatchTowr says the flaw sits in the PostgreSQL Sidecar Service Endpoint and affects Splunk Enterprise and Splunk Cloud Platform versions called out in the advisory, with Splunk Enterprise on AWS shipping the service installed and enabled by default. That makes some deployments exposed out of the box and puts logs, configs, and other platform files at risk on systems many teams rely on for detection and monitoring.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: in Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and… EPSS 97% (100th percentile).
CISA federal remediation date Jun 21
1 source covering this story
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
On June 10th, Splunk published this CVE-2026-20253 advisory: It has everything that we love: * No authentication
Part of the PlainSec briefing for 2026-06-13