---
schema: 1
kind: vulnerability
title: >
  CVE-2026-20253 — Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar
  proxy
headline: >
  CVE-2026-20253 — Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar
  proxy
summary: >
  Splunk Enterprise pre-auth RCE (CVE-2026-20253, CVSS 9.8) — your SIEM is the target. watchTowr
  detailed an unauthenticated path that proxies an internal PostgreSQL-sidecar REST API with empty
  credentials, reaching code execution during a crafted backup/restore; Splunk-on-AWS is
  vulnerable out of the box (watchTowr Labs, 2026-06-12).
discovered_at: "2026-06-14T05:00:04Z"
updated_at: "2026-06-20T05:12:19Z"
event_date: 2026-06-12
run_id: 2026-06-14-e1d80e78
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - default-config
  - patch-available
  - actively-exploited
  - cisa-kev
regions:
  - global
  - europe
sectors:
  - public-sector
  - finance
entities: []
techniques: []
affected_products: []
cves:
  - id: CVE-2026-20253
    cvss: "9.8"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://advisory.splunk.com/advisories/SVD-2026-0603"
    publisher: Splunk SVD-2026-0603
    role: primary
  - url: "https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/"
    publisher: watchTowr Labs
    role: corroborating
  - url: "https://www.securityweek.com/splunk-enterprise-vulnerability-exploited-in-attacks-days-after-disclosure/"
    publisher: SecurityWeek
    role: corroborating
closed_sources: []
evidence:
  - quote: "UPDATE (originally covered 2026-06-14): Splunk PSIRT and NCSC-NL have confirmed that CVE-2026-20253 (CVSS 9.8) — the Splunk Enterprise pre-auth RCE first covered on 2026-06-14 — is now under limited targeted exploitation in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog …"
    publisher: ctipilot v2 brief (migrated)
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Upgrade Splunk Enterprise to 10.4.0 / 10.2.4 / 10.0.7, AWS-hosted instances first (CVE-2026-20253).** Pre-auth RCE via the default-enabled PostgreSQL sidecar proxy; ensure no Splunk web/management interface is internet-facing, confirm the sidecar stays disabled on on-prem installs that don't use it, and forward Splunk's own access logs off-box. Hunt `/en-US/splunkd/__raw/v1/postgres/` requests with empty Basic-auth from non-loopback sources."
  - "**Treat Splunk CVE-2026-20253 (CVSS 9.8, now CISA KEV) as emergency, not routine** — confirmed limited targeted exploitation of a pre-auth RCE on the SIEM platform itself. Patch to Splunk Enterprise 10.4.0 / 10.2.4 / 10.0.7, restrict search-job submission to analyst accounts, verify search-head/indexer segmentation."
updates:
  - at: "2026-06-20T05:12:19Z"
    run_id: 2026-06-20-4cfd00ef
    type: update
    summary: >
      Splunk Enterprise CVE-2026-20253 (pre-auth RCE) now under confirmed limited targeted
      exploitation per Splunk PSIRT and NCSC-NL — patch urgency for SOC SIEM platforms jumps from
      routine to emergency (§ 4).
    fields:
      - actions
      - cves
      - evidence
      - regions
      - sectors
      - sources
      - tags
      - body
    merged_from: 2026-06-20/splunk-cve-2026-20253-now-under-confirmed-limited-targeted-e
migrated_from: briefs/2026-06-14.md
---

CVE-2026-20253 (CVSS 9.8, CWE-306 Missing Authentication for Critical Function) is an unauthenticated remote code execution flaw in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3 ([Splunk SVD-2026-0603, 2026-06-10](https://advisory.splunk.com/advisories/SVD-2026-0603)). watchTowr Labs, which published the full mechanism on 12 June, reports that Splunk-on-AWS is vulnerable out of the box because the PostgreSQL sidecar is enabled by default ([watchTowr Labs, 2026-06-12](https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/)). This brief's deep dive (§ 5) covers the sidecar-proxy chain, detection and patching in detail; fixed versions are 10.4.0, 10.2.4 and 10.0.7.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-10520 | Ivanti Sentry (MDM gateway) | 10.0 | n/a | Yes (2026-06-11) | Yes — gateways backdoored (Shadowserver) | R10.5.2 / R10.6.2 / R10.7.1 | [Security Affairs](https://securityaffairs.com/193557/security/u-s-cisa-adds-ivanti-sentry-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-patching-by-june-14.html) |
| CVE-2026-10795 | UpdraftPlus WordPress plugin ≤ 1.26.4 | 8.1 | n/a | No | Not confirmed ITW; mechanism public, Wordfence preventive rules | 1.26.5 | [WPScan](https://wpscan.com/vulnerability/68addf8c-9ea6-4b62-9f85-e95350b3992e/) |
| CVE-2026-20253 | Splunk Enterprise 10.0.x / 10.2.x | 9.8 | n/a | No | PoC/analysis public; no ITW reported | 10.4.0 / 10.2.4 / 10.0.7 | [Splunk SVD-2026-0603](https://advisory.splunk.com/advisories/SVD-2026-0603) |

*(CVE-2026-10520 is carried as the § 0 Immediate Action and § 4 UPDATE; included here for the gate-clearing exploitation picture. CVEs that did not clear a § 2 inclusion gate this run — CVE-2026-47210 (vm2) and CVE-2026-12183 (BUK TS-G) — are noted in § 7.)*

## Update — 2026-06-20T05:12:19Z

Splunk PSIRT and NCSC-NL have confirmed that CVE-2026-20253 (CVSS 9.8) — the Splunk Enterprise pre-auth RCE first covered on 2026-06-14 — is now under limited targeted exploitation in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-06-18, moving it from "disclosed, no known exploitation" to active-exploitation status ([Splunk PSIRT SVD-2026-0603, 2026-06-18](https://advisory.splunk.com/advisories/SVD-2026-0603); [SecurityWeek, 2026-06-19](https://www.securityweek.com/splunk-enterprise-vulnerability-exploited-in-attacks-days-after-disclosure/)).

The vulnerability is an unauthenticated arbitrary file-creation/truncation flaw in a PostgreSQL sidecar service endpoint that chains to remote code execution; it affects the 10.0.x and 10.2.x branches and is fixed in Splunk Enterprise 10.4.0 / 10.2.4 / 10.0.7, available since 2026-06-14. The exploitation confirmation plus KEV listing raises this from a routine patch-cycle item to emergency priority, particularly because Splunk is a standard SIEM platform inside CH/EU public-sector SOC environments — a compromised search head sits at the centre of detection and log visibility. Restrict search-job submission to authorised analyst accounts and verify indexer/search-head network segmentation while patching.
