Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has published security patches to address a significant security flaw in Splunk Enterprise that could be abused to execute unauthenticated file activities and potentially remote code execution.

According to the CVSS scoring methodology, the vulnerability, identified as CVE-2026-20253, has a rating of 9.8.

An unauthorized user might create or truncate arbitrary files using a PostgreSQL sidecar service endpoint in Splunk Enterprise versions lower than 10.2.4 and 10.0.7, according to a Splunk notice this week.

Due to the PostgreSQL sidecar service endpoint’s absence of authentication constraints, file operations can be invoked without credentials by any network-reachable user.

The issue has been addressed in the following versions –

  • Splunk Enterprise 10.0.0 to 10.0.6 – Fixed in 10.0.7
  • Splunk Enterprise 10.2.0 to 10.2.3 – Fixed in 10.2.4
  • Splunk Enterprise 10.4 – Not affected

Splunk, a division of Cisco, stated that because Splunk Cloud does not employ Postgres sidecars, it is not affected by the vulnerability read more about Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *