Splunk issued urgent fixes for CVE-2026-20253, a critical CVSS 9.8 vulnerability in Splunk Enterprise that allows unauthenticated arbitrary file creation and truncation through a PostgreSQL sidecar service endpoint missing authentication controls. The flaw affects supported Splunk Enterprise releases prior to 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13 depending on branch, and Splunk said Splunk Cloud is not affected because it does not use Postgres sidecars. Splunk and national cyber authorities urged administrators to apply updates immediately, noting that no vendor detections or workarounds were initially available for the core issue.
Public technical analysis from watchTowr Labs showed the bug can be reached through Splunk Web on port 8000, which proxies requests to localhost-only PostgreSQL recovery endpoints, enabling attackers to abuse /v1/postgres/recovery/backup and /restore for filesystem access. Researchers demonstrated a full pre-auth exploitation chain that used path traversal, PostgreSQL connection-string injection, local .pgpass credentials, and PostgreSQL large-object export to gain arbitrary file write as the splunk user, then overwrite a Splunk Python script to achieve remote code execution. Splunk also disclosed additional Enterprise flaws including CVE-2026-20251 (CVSS 8.8) in the Splunk Secure Gateway app due to unsafe jsonpickle deserialization, plus stored XSS and SSRF issues, prompting guidance to patch quickly, restrict dashboard creation and web exposure, and disable or remove vulnerable components where immediate upgrades are not possible.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-19, a Rapid7 Metasploit Framework pull request proposed a scanner module to detect CVE-2026-20253 in Splunk’s PostgreSQL sidecar recovery endpoint. The module description showed unauthenticated file-operation behavior on vulnerable versions such as 10.2.3 and noted that patched 10.2.4 requires a Splunk token in the Authorization header.
Splunk subsequently confirmed limited exploitation of CVE-2026-20253 in June 2026 and urged customers to upgrade immediately. The confirmation followed earlier public reporting and CISA action around the actively exploited flaw.
Following its KEV listing, CISA required federal civilian agencies to remediate CVE-2026-20253 by 2026-06-21 under Binding Operational Directive 26-04. The agency warned that internet-exposed Splunk Enterprise instances were especially at risk and urged immediate mitigation and forensic triage.
On 2026-06-18, CISA added Splunk Enterprise vulnerability CVE-2026-20253 to its Known Exploited Vulnerabilities catalog. The KEV update identified the flaw as a missing authentication issue enabling arbitrary file creation or truncation via a PostgreSQL sidecar endpoint and directed organizations to apply vendor mitigations under BOD 26-04.
On 2026-06-16, Resecurity reported active exploitation of CVE-2026-20253, describing the flaw as a pre-authentication remote code execution issue affecting Splunk Enterprise and certain Splunk Cloud Platform releases. The report said exploitation could enable arbitrary code execution, data exposure or manipulation, persistence, credential theft, defense evasion, and lateral movement, and urged immediate mitigation and investigation for compromise.
On 2026-06-13, watchTowr Labs publicly described how CVE-2026-20253 could be exploited through Splunk’s web proxy to reach localhost PostgreSQL sidecar endpoints and gain arbitrary file operations. The researchers showed escalation via PostgreSQL connection-string injection, abuse of local .pgpass credentials, and malicious SQL restoration to obtain arbitrary file write as the splunk user.
watchTowr’s proof of concept showed the arbitrary file write could be turned into remote code execution by overwriting a Splunk Python script that is executed by the product. The researchers also released a limited detection script to test whether access to the vulnerable backup endpoint was blocked.
On 2026-06-12, a GitHub pull request for ProjectDiscovery nuclei templates referenced CVE-2026-20253. The provided content indicates workflow activity around adding detection content for the Splunk vulnerability, though technical details are truncated.
On 2026-06-12, Splunk updated its advisory to state that Splunk Cloud is not affected because it does not use Postgres sidecars. This narrowed the impact of CVE-2026-20253 to affected Splunk Enterprise deployments.
On 2026-06-10, Splunk also disclosed multiple other high and critical Splunk Enterprise vulnerabilities, including CVE-2026-20251, CVE-2026-20258, and CVE-2026-20252. The issues included unsafe deserialization leading to remote code execution, stored cross-site scripting, server-side request forgery, and dashboard-related data exfiltration risks.
On 2026-06-10, Splunk disclosed CVE-2026-20253, a critical Splunk Enterprise flaw caused by missing authentication on a PostgreSQL sidecar service endpoint. Splunk said the issue allows unauthenticated arbitrary file creation and truncation and recommended upgrading to fixed versions 10.4.0, 10.2.4, 10.0.7, or later.
On 2026-06-10, Splunk published security advisories covering vulnerabilities in Splunk SOAR, Splunk Enterprise, and Splunk Cloud Platform. The Canadian Centre for Cyber Security urged administrators to review Splunk’s advisories and apply the necessary updates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
28 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourcegithub.com
Open sourcecyber.gc.ca
Open sourceadvisory.splunk.com
Open sourcecve.org
Open sourcelabs.watchtowr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.