Tag: Splunk Enterprise Flaw

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
News

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Splunk has published security patches to address a significant security flaw in Splunk Enterprise that could be abused to execute unauthenticated file activities and potentially remote code execution. According to the CVSS scoring methodology, the vulnerability, identified as CVE-2026-20253, has a rating of 9.8. An unauthorized user might create or truncate arbitrary files using a PostgreSQL sidecar service endpoint in Splunk Enterprise versions lower than 10.2.4 and 10.0.7, according to a Splunk notice this week. Due to the PostgreSQL sidecar service endpoint's absence of authentication constraints, file operations can be invoked without credentials by any network-reachable user. The issue has been addressed in the following versions - Splunk Enterprise 10.0.0 to 10.0.6 -...