ctipilot.ch

Splunk Enterprise pre-auth RCE via unauthenticated PostgreSQL sidecar REST API proxied by web tier, CVSS 9.8

cve · CVE-2026-20253 single-source

Coverage timeline
5
first 2026-06-14 → last 2026-06-22
Peak priority
high
3 high · 2 notable
Sources cited
8
7 hosts
Sections touched
5
deep-dive, trending-vulnerabilities, updates
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.1 · see below

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-06-14/splunk-enterprise-cve-2026-20253-pre-auth-rce-in-the-siem-vi · ATT&CK page ↗

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-06-14/splunk-enterprise-cve-2026-20253-pre-auth-rce-in-the-siem-vi · ATT&CK page ↗

Story timeline

  1. 2026-06-22CVE-2026-20253 — Splunk Enterprise pre-auth RCE flips to confirmed exploitation and CISA KEV
    weekly-top-stories
  2. 2026-06-20Splunk CVE-2026-20253 now under confirmed limited targeted exploitation
    updates
  3. 2026-06-14Splunk Enterprise CVE-2026-20253: pre-auth RCE in the SIEM via an unauthenticated PostgreSQL sidecar proxy
    deep-dive
  4. 2026-06-14CVE-2026-20253 — Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy
    trending-vulnerabilities
  5. 2026-06-14CVE-2026-20253 — Splunk Enterprise: unauthenticated arbitrary file creation/truncation via the PostgreSQL sidecar proxy
    weekly-vuln-rollup

Where this entity is cited

  • weekly-vuln-rollup1
  • trending-vulnerabilities1
  • deep-dive1
  • updates1
  • weekly-top-stories1

Source distribution

  • attack.mitre.org2 (25%)
  • advisory.splunk.com1 (12%)
  • labs.watchtowr.com1 (12%)
  • securityaffairs.com1 (12%)
  • securityweek.com1 (12%)
  • thehackernews.com1 (12%)
  • wpscan.com1 (12%)

explore in graph

Entries about Splunk Enterprise pre-auth RCE via unauthenticated PostgreSQL sidecar REST API proxied by web tier, CVSS 9.8 (5)

2026-06-22 · view entry permalink →

HIGHCVE-2026-20253exploited

CVE-2026-20253 — Splunk Enterprise pre-auth RCE flips to confirmed exploitation and CISA KEV

If you did nothing this week: if you run an internet-reachable Splunk Enterprise search head on 10.0.x or 10.2.x, you are now exposed to an unauthenticated remote-code-execution path that is being exploited in the wild — and a compromised search head sits at the centre of your detection and log visibility.

When CVE-2026-20253 (CVSS 9.8, CWE-306) was first covered on 2026-06-14 it was a disclosure-plus-patch story. This week Splunk PSIRT confirmed limited exploitation, CISA added it to the KEV catalog on 2026-06-18, and NCSC-NL corroborated (Splunk PSIRT SVD-2026-0603; SecurityWeek, 2026-06-19; daily 06-20). The flaw is an unauthenticated arbitrary file-creation/truncation primitive reachable through a PostgreSQL sidecar service endpoint that lacks authentication controls, chaining to RCE. It affects Splunk Enterprise 10.0 below 10.0.7 and 10.2 below 10.2.4; fixes (10.4.0 / 10.2.4 / 10.0.7) have been available since 2026-06-14.

The operational weight here is the platform, not the CVSS: Splunk is a standard SIEM backbone inside CH/EU public-sector SOCs, and an attacker who lands pre-auth code execution on the search-head tier owns the analytics plane that defenders rely on. Patch on emergency cadence, restrict search-job submission to authorised analyst accounts, and verify indexer/search-head network segmentation so the PostgreSQL sidecar is not network-reachable from untrusted zones.

In June 2026, the Splunk Product Security Incident Response Team (PSIRT) became aware of limited exploitation of this vulnerability.

an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint

Splunk PSIRT
synthesis22 Jun 00:14Zmulti-sourceOpen finding ↗

2026-06-20 · view entry permalink →

HIGHCVE-2026-20253exploitedupdate

Splunk CVE-2026-20253 now under confirmed limited targeted exploitation

UPDATE · originally covered CVE-2026-20253 — Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy (2026-06-14)

Splunk PSIRT and NCSC-NL have confirmed that CVE-2026-20253 (CVSS 9.8) — the Splunk Enterprise pre-auth RCE first covered on 2026-06-14 — is now under limited targeted exploitation in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-18, moving it from "disclosed, no known exploitation" to active-exploitation status (Splunk PSIRT SVD-2026-0603, 2026-06-18; SecurityWeek, 2026-06-19).

The vulnerability is an unauthenticated arbitrary file-creation/truncation flaw in a PostgreSQL sidecar service endpoint that chains to remote code execution; it affects the 10.0.x and 10.2.x branches and is fixed in Splunk Enterprise 10.4.0 / 10.2.4 / 10.0.7, available since 2026-06-14. The exploitation confirmation plus KEV listing raises this from a routine patch-cycle item to emergency priority, particularly because Splunk is a standard SIEM platform inside CH/EU public-sector SOC environments — a compromised search head sits at the centre of detection and log visibility. Restrict search-job submission to authorised analyst accounts and verify indexer/search-head network segmentation while patching.

UPDATE (originally covered 2026-06-14): Splunk PSIRT and NCSC-NL have confirmed that CVE-2026-20253 (CVSS 9.8) — the Splunk Enterprise pre-auth RCE first covered on 2026-06-14 — is now under limited targeted exploitation in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog …

ctipilot v2 brief (migrated)
vulnerability20 Jun 05:12Zmulti-sourceOpen finding ↗

2026-06-14 · view entry permalink →

CVE-2026-20253 — Splunk Enterprise: unauthenticated arbitrary file creation/truncation via the PostgreSQL sidecar proxy

Disclosed this week and not yet seen exploited, but it belongs in the operationally-critical tier because Splunk is the SIEM/log-analytics backbone in many SOCs — including public-sector ones — and an unauthenticated flaw on your detection platform is a defender's worst-case blind spot. Per Splunk's advisory, CVE-2026-20253 (CVSS 9.8, CWE-306 Missing Authentication for Critical Function) lets an unauthenticated actor create or truncate arbitrary files via the bundled PostgreSQL sidecar proxy in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3 — a primitive that can be chained toward code execution but which the advisory itself scopes as file creation/truncation rather than direct RCE (Splunk SVD-2026-0603; daily 06-14). Patch to the fixed maintenance releases; where the Splunk web/API tier is internet-reachable, restrict it now — a compromised SIEM lets an attacker both pivot and rewrite the evidence.

vulnerability14 Jun 23:57Zsingle-sourceOpen finding ↗

Earlier coverage (2)