CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to Daily brief 2026-06-14
HIGHCVE-2026-20253exploitedupdatedvulnerability

CVE-2026-20253, Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy

Defender actions

  • Upgrade Splunk Enterprise to 10.4.0 / 10.2.4 / 10.0.7, AWS-hosted instances first (CVE-2026-20253). Pre-auth RCE via the default-enabled PostgreSQL sidecar proxy; ensure no Splunk web/management interface is internet-facing, confirm the sidecar stays disabled on on-prem installs that don't use it, and forward Splunk's own access logs off-box. Hunt /en-US/splunkd/__raw/v1/postgres/ requests with empty Basic-auth from non-loopback sources.
  • Treat Splunk CVE-2026-20253 (CVSS 9.8, now CISA KEV) as emergency, not routine, confirmed limited targeted exploitation of a pre-auth RCE on the SIEM platform itself. Patch to Splunk Enterprise 10.4.0 / 10.2.4 / 10.0.7, restrict search-job submission to analyst accounts, verify search-head/indexer segmentation.

Analysis

CVE-2026-20253 (CVSS 9.8, CWE-306 Missing Authentication for Critical Function) is an unauthenticated remote code execution flaw in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3 (Splunk SVD-2026-0603, 2026-06-10). watchTowr Labs, which published the full mechanism on 12 June, reports that Splunk-on-AWS is vulnerable out of the box because the PostgreSQL sidecar is enabled by default (watchTowr Labs, 2026-06-12). This brief's deep dive (§ 5) covers the sidecar-proxy chain, detection and patching in detail; fixed versions are 10.4.0, 10.2.4 and 10.0.7.

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-10520 Ivanti Sentry (MDM gateway) 10.0 n/a Yes (2026-06-11) Yes, gateways backdoored (Shadowserver) R10.5.2 / R10.6.2 / R10.7.1 Security Affairs
CVE-2026-10795 UpdraftPlus WordPress plugin ≤ 1.26.4 8.1 n/a No Not confirmed ITW; mechanism public, Wordfence preventive rules 1.26.5 WPScan
CVE-2026-20253 Splunk Enterprise 10.0.x / 10.2.x 9.8 n/a No PoC/analysis public; no ITW reported 10.4.0 / 10.2.4 / 10.0.7 Splunk SVD-2026-0603

(CVE-2026-10520 is carried as the § 0 Immediate Action and § 4 UPDATE; included here for the gate-clearing exploitation picture. CVEs that did not clear a § 2 inclusion gate this run, CVE-2026-47210 (vm2) and CVE-2026-12183 (BUK TS-G), are noted in § 7.)

Cited evidence

UPDATE (originally covered 2026-06-14): Splunk PSIRT and NCSC-NL have confirmed that CVE-2026-20253 (CVSS 9.8) (the Splunk Enterprise pre-auth RCE first covered on 2026-06-14) is now under limited targeted exploitation in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog …

ctipilot v2 brief (migrated)

Updates1

Update

Splunk PSIRT and NCSC-NL have confirmed that CVE-2026-20253 (CVSS 9.8) (the Splunk Enterprise pre-auth RCE first covered on 2026-06-14) is now under limited targeted exploitation in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-18, moving it from "disclosed, no known exploitation" to active-exploitation status (Splunk PSIRT SVD-2026-0603, 2026-06-18; SecurityWeek, 2026-06-19).

The vulnerability is an unauthenticated arbitrary file-creation/truncation flaw in a PostgreSQL sidecar service endpoint that chains to remote code execution; it affects the 10.0.x and 10.2.x branches and is fixed in Splunk Enterprise 10.4.0 / 10.2.4 / 10.0.7, available since 2026-06-14. The exploitation confirmation plus KEV listing raises this from a routine patch-cycle item to emergency priority, particularly because Splunk is a standard SIEM platform inside CH/EU public-sector SOC environments; a compromised search head sits at the centre of detection and log visibility. Restrict search-job submission to authorised analyst accounts and verify indexer/search-head network segmentation while patching.

Sources3

Revision history

  1. Published 2026-06-14-e1d80e78
  2. Update 2026-06-20-4cfd00ef

    Splunk Enterprise CVE-2026-20253 (pre-auth RCE) now under confirmed limited targeted exploitation per Splunk PSIRT and NCSC-NL, patch urgency for SOC SIEM platforms jumps from routine to emergency (§ 4).

    Changed: actions cves evidence regions sectors sources tags body

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.