Splunk disclosed CVE-2026-20253, a critical unauthenticated vulnerability in the PostgreSQL sidecar component of Splunk Enterprise and Splunk Cloud Platform that lets a network-reachable attacker create or truncate arbitrary files on the host. The flaw, tracked as VULN-67169 and SVD-2026-0603, is rated CVSS 9.8 and affects Splunk Enterprise 10.2.0 through 10.2.3 and 10.0.0 through 10.0.6, as well as Splunk Cloud Platform versions below 10.4.2604.3 and below 10.2.2510.14. Splunk said fixed versions are available, cloud instances are being actively patched, and no workaround exists other than upgrading.
Splunk also published security content tied to SVD-2026-0603 to help defenders simulate and validate detection of the exposed sidecar behavior, including replayable attack data mapped to MITRE ATT&CK T1210. Separately, the company disclosed CVE-2026-20140, a Windows-only local privilege-escalation flaw in Splunk Enterprise caused by DLL search-order hijacking during service startup; that issue can allow a low-privileged local user to gain NT AUTHORITY\SYSTEM privileges and has been fixed in supported branches, with Splunk advising upgrades, tighter write permissions, and monitoring for suspicious DLL drops and service restarts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Splunk Research published SVD-2026-0603 as attack simulation material for the unauthenticated arbitrary file creation issue in the PostgreSQL sidecar service. The dataset provides replay and import guidance for testing and is explicitly described as simulation content rather than an incident report.
Splunk disclosed CVE-2026-20253, a critical unauthenticated vulnerability in Splunk Enterprise and Splunk Cloud Platform that allows arbitrary file creation or truncation through an exposed PostgreSQL sidecar endpoint. Splunk released fixed versions for affected Enterprise branches and said it was actively patching affected cloud instances, with no workaround available beyond upgrading.
Splunk disclosed CVE-2026-20140, a high-severity local privilege-escalation vulnerability affecting Splunk Enterprise for Windows. The company assigned advisory SVD-2026-0205 and released fixed versions across supported branches, noting that non-Windows deployments are not impacted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourcezeropath.com
Open sourceop-c.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.