CRITICAL 9.8CISA KEV — Actively Exploited

CVE-2026-20253: Critical Unauthenticated File Access in Splunk Enterprise – Patch Now

An unauthenticated attacker can create or delete files on Splunk Enterprise systems through an unprotected PostgreSQL service interface. The vulnerability affects Splunk 10.2 before version 10.2.4 and Splunk 10 before 10.0.7. Because no credentials are required and the service is accessible over the network, any attacker who can reach the affected system can exploit this without authentication. Splunk 9.4 and earlier versions are unaffected.

Source data · NVD / CISA · public domain

CVSS
3.1 · 9.8 CRITICAL · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-306
Affected products
1 configuration(s)
Published / Modified
2026-06-10 / 2026-06-19
KEV due date
2026-06-21 (added 2026-06-18)

NVD description (verbatim)

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.

3 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-20253 is a missing authentication vulnerability (CWE-306) in the PostgreSQL sidecar service endpoint within Splunk Enterprise. The endpoint fails to enforce authentication controls on file operation functions, allowing unauthenticated network users to invoke arbitrary file creation and truncation. The attack surface is the network-accessible sidecar service; exploitation requires no special privileges or user interaction. The vulnerability carries a CVSS 3.1 score of 9.8 (Critical) reflecting network-based, unauthenticated, low-complexity attack potential with high impact to confidentiality, integrity, and availability.

Business impact

An attacker exploiting this vulnerability can read, modify, or destroy critical files on an affected Splunk instance, leading to data breach, configuration tampering, denial of service, or complete system compromise. In environments where Splunk is a central logging or security monitoring hub, file-level access could enable an attacker to manipulate audit logs, disable security controls, or establish persistence. This is particularly severe because no credentials or prior system access are required—any network-reachable attacker can initiate the attack.

Affected systems

Splunk Enterprise 10.2.0 through 10.2.3 and Splunk Enterprise 10.0.0 through 10.0.6 are affected. Splunk Enterprise versions 9.4 and earlier are not affected. Organizations should inventory systems running Splunk 10.x and confirm whether they are below the patched versions. Splunk Cloud is a managed offering and requires coordination with Splunk support for deployment status.

Exploitability

This vulnerability is highly exploitable. It requires only network access to the PostgreSQL sidecar service endpoint—no authentication, no special tools, and no user interaction. The CISA KEV catalog added this vulnerability on 2026-06-18 with a due date of 2026-06-21, indicating active exploitation in the wild or high confidence in weaponization. Organizations should treat this as an immediate, top-priority threat.

Remediation

Upgrade Splunk Enterprise 10.2.x to version 10.2.4 or later, or upgrade Splunk Enterprise 10.0.x to version 10.0.7 or later. If immediate patching is not possible, disable the PostgreSQL sidecar service as a temporary mitigation. This may impact dependent features; test thoroughly in a non-production environment first and coordinate with Splunk support to understand any functional implications of disabling the service.

Patch guidance

Apply the latest Splunk Enterprise update for your version branch: 10.2.4+ for the 10.2 line, or 10.0.7+ for the 10.0 line. Verify against the official Splunk security advisory to confirm patch availability and any prerequisites. Plan patching immediately given the CISA KEV status and 2026-06-21 due date. Test in a development or staging environment before production rollout. If you run Splunk Cloud, contact Splunk support to confirm when the fix will be deployed to your instance.

Detection guidance

Monitor network traffic to the PostgreSQL sidecar service port for unauthorized or suspicious connections from unexpected sources. Look for POST or other requests to the sidecar endpoint from unauthenticated clients. Enable detailed logging on the Splunk instance if available and search for file creation, modification, or truncation events that correlate with suspicious network activity. Intrusion detection systems and network behavior analytics may flag anomalous file operations or unauthorized sidecar service access.

Why prioritize this

This vulnerability scores a CVSS 9.8 Critical with zero authentication requirements and network-accessible attack surface. It is actively tracked in CISA's Known Exploited Vulnerabilities catalog with a remediation due date of 2026-06-21. The ability for any network-reachable attacker to create or truncate arbitrary files poses an immediate risk to confidentiality, integrity, and availability. Organizations must treat this as the highest remediation priority.

Risk score, explained

The CVSS 3.1 score of 9.8 reflects a network-accessible vulnerability requiring no authentication (PR:N, AU:N) and no user interaction (UI:N), with high impact to all three security dimensions: confidentiality (file read), integrity (file creation/truncation), and availability (file deletion or system disruption). The combination of ease of exploitation, lack of prerequisites, and severity of impact justifies a Critical rating. Inclusion in CISA KEV further elevates operational risk by confirming real-world exploitation.

Frequently asked questions

Do I need credentials to exploit this vulnerability?

No. The PostgreSQL sidecar service endpoint lacks authentication controls, so any attacker with network access to the affected Splunk instance can invoke file operations without providing credentials.

Which Splunk versions should I prioritize for patching?

Splunk Enterprise 10.2.0–10.2.3 and 10.0.0–10.0.6 are vulnerable. Upgrade 10.2.x to 10.2.4 or later, and 10.0.x to 10.0.7 or later. Splunk 9.4 and earlier are not affected.

What should I do if I cannot patch immediately?

Disable the PostgreSQL sidecar service as an interim mitigation. Contact Splunk support first to understand the impact on any dependent features, and test the mitigation in a non-production environment before applying it to production.

Is this vulnerability being actively exploited?

Yes. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-06-18, indicating active exploitation or high confidence of weaponization. Remediation is due by 2026-06-21.

This analysis is based on the CVE details and CISA KEV information available as of the publication date. Patch version numbers and remediation guidance must be verified against the official Splunk security advisory and vendor documentation. Exploitability claims are informed by CISA KEV status but do not constitute proof of active exploitation in every environment. Organizations should conduct their own risk assessment and testing before applying patches or mitigations. This content is provided for informational purposes and does not constitute professional security advice. Source: NVD (public-domain), retrieved 2026-07-20. Analysis generated by SEC.co (claude-haiku-4-5).

Preview — this page is review (quality 0.999). high-value: hold for review.