Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilityproof-of-concept-releaserapid-weaponization

Critical Splunk Enterprise Flaw Exposes Pre-Auth File Write and RCE Path

Updated 1d agoFirst seen Jun 11, 202626 sources

Splunk issued urgent fixes for CVE-2026-20253, a critical CVSS 9.8 vulnerability in Splunk Enterprise that allows unauthenticated arbitrary file creation and truncation through a PostgreSQL sidecar service endpoint missing authentication controls. The flaw affects supported Splunk Enterprise releases prior to 10.4.0, 10.2.4, 10.0.7, 9.4.12, and 9.3.13 depending on branch, and Splunk said Splunk Cloud is not affected because it does not use Postgres sidecars. Splunk and national cyber authorities urged administrators to apply updates immediately, noting that no vendor detections or workarounds were initially available for the core issue.

Public technical analysis from watchTowr Labs showed the bug can be reached through Splunk Web on port 8000, which proxies requests to localhost-only PostgreSQL recovery endpoints, enabling attackers to abuse /v1/postgres/recovery/backup and /restore for filesystem access. Researchers demonstrated a full pre-auth exploitation chain that used path traversal, PostgreSQL connection-string injection, local .pgpass credentials, and PostgreSQL large-object export to gain arbitrary file write as the splunk user, then overwrite a Splunk Python script to achieve remote code execution. Splunk also disclosed additional Enterprise flaws including CVE-2026-20251 (CVSS 8.8) in the Splunk Secure Gateway app due to unsafe jsonpickle deserialization, plus stored XSS and SSRF issues, prompting guidance to patch quickly, restrict dashboard creation and web exposure, and disable or remove vulnerable components where immediate upgrades are not possible.

Share:
Critical Splunk Enterprise Flaw Exposes Pre-Auth File Write and RCE Path
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Jun 19, 202611d ago

Metasploit scanner pull request opened for CVE-2026-20253

On 2026-06-19, a Rapid7 Metasploit Framework pull request proposed a scanner module to detect CVE-2026-20253 in Splunk’s PostgreSQL sidecar recovery endpoint. The module description showed unauthenticated file-operation behavior on vulnerable versions such as 10.2.3 and noted that patched 10.2.4 requires a Splunk token in the Authorization header.

Add Splunk PostgreSQL sidecar unauthenticated file operation scanner (CVE-2026-20253) by kenlacroix · Pull Request #21586 · rapid7/metasploit-framework · GitHub

Splunk confirms limited exploitation of CVE-2026-20253

Splunk subsequently confirmed limited exploitation of CVE-2026-20253 in June 2026 and urged customers to upgrade immediately. The confirmation followed earlier public reporting and CISA action around the actively exploited flaw.

CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
Jun 18, 202612d ago

CISA sets June 21 remediation deadline for CVE-2026-20253

Following its KEV listing, CISA required federal civilian agencies to remediate CVE-2026-20253 by 2026-06-21 under Binding Operational Directive 26-04. The agency warned that internet-exposed Splunk Enterprise instances were especially at risk and urged immediate mitigation and forensic triage.

CISA Warns of Splunk Enterprise Critical Function Vulnerability Actively Exploited in Attacks

CISA adds CVE-2026-20253 to KEV catalog

On 2026-06-18, CISA added Splunk Enterprise vulnerability CVE-2026-20253 to its Known Exploited Vulnerabilities catalog. The KEV update identified the flaw as a missing authentication issue enabling arbitrary file creation or truncation via a PostgreSQL sidecar endpoint and directed organizations to apply vendor mitigations under BOD 26-04.

Add Updated KEV Files for 2026-06-18 · cisagov/kev-data@ca7194b · GitHub
Jun 16, 202614d ago

Resecurity reports active exploitation of CVE-2026-20253

On 2026-06-16, Resecurity reported active exploitation of CVE-2026-20253, describing the flaw as a pre-authentication remote code execution issue affecting Splunk Enterprise and certain Splunk Cloud Platform releases. The report said exploitation could enable arbitrary code execution, data exposure or manipulation, persistence, credential theft, defense evasion, and lateral movement, and urged immediate mitigation and investigation for compromise.

Resecurity | CVE-2026-20253: Splunk Enterprise Pre-Authentication Remote Code Execution
Jun 13, 202617d ago

watchTowr publicly details CVE-2026-20253 exploit chain

On 2026-06-13, watchTowr Labs publicly described how CVE-2026-20253 could be exploited through Splunk’s web proxy to reach localhost PostgreSQL sidecar endpoints and gain arbitrary file operations. The researchers showed escalation via PostgreSQL connection-string injection, abuse of local .pgpass credentials, and malicious SQL restoration to obtain arbitrary file write as the splunk user.

CVE-2026-20253: Splunk Pre-Auth RCE via PostgreSQL Sidecar | The CyberSec Guru
Jun 12, 202617d ago

watchTowr demonstrates remote code execution from the flaw

watchTowr’s proof of concept showed the arbitrary file write could be turned into remote code execution by overwriting a Splunk Python script that is executed by the product. The researchers also released a limited detection script to test whether access to the vulnerable backup endpoint was blocked.

Watchtowr Labs

Nuclei template pull request opened for CVE-2026-20253

On 2026-06-12, a GitHub pull request for ProjectDiscovery nuclei templates referenced CVE-2026-20253. The provided content indicates workflow activity around adding detection content for the Splunk vulnerability, though technical details are truncated.

CVE-2026-20253 - Splunk Enterprise & Cloud Platform - Unrestricted File Upload by DhiyaneshGeek · Pull Request #16389 · projectdiscovery/nuclei-templates · GitHub

Splunk clarifies Splunk Cloud is not affected by CVE-2026-20253

On 2026-06-12, Splunk updated its advisory to state that Splunk Cloud is not affected because it does not use Postgres sidecars. This narrowed the impact of CVE-2026-20253 to affected Splunk Enterprise deployments.

SVD-2026-0603 | Splunk Vulnerability Disclosure
Jun 10, 202620d ago

Splunk discloses additional Enterprise flaws including RCE, XSS, and SSRF

On 2026-06-10, Splunk also disclosed multiple other high and critical Splunk Enterprise vulnerabilities, including CVE-2026-20251, CVE-2026-20258, and CVE-2026-20252. The issues included unsafe deserialization leading to remote code execution, stored cross-site scripting, server-side request forgery, and dashboard-related data exfiltration risks.

Multiple Splunk Enterprise Vulnerabilities Allow Attackers to Execute Malicious Script

Splunk publishes advisory for CVE-2026-20253

On 2026-06-10, Splunk disclosed CVE-2026-20253, a critical Splunk Enterprise flaw caused by missing authentication on a PostgreSQL sidecar service endpoint. Splunk said the issue allows unauthenticated arbitrary file creation and truncation and recommended upgrading to fixed versions 10.4.0, 10.2.4, 10.0.7, or later.

SVD-2026-0603 | Splunk Vulnerability Disclosure

Splunk discloses multiple product vulnerabilities and urges updates

On 2026-06-10, Splunk published security advisories covering vulnerabilities in Splunk SOAR, Splunk Enterprise, and Splunk Cloud Platform. The Canadian Centre for Cyber Security urged administrators to review Splunk’s advisories and apply the necessary updates.

Splunk security advisory (AV26-586) - Canadian Centre for Cyber Security
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

32 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Critical Splunk Enterprise Flaw Exposes Pre-Auth File Write and RCE Path | Mallory