Critical CVE-2026-20253 (CVSS 9.8) allows unauthenticated file manipulation in Splunk Enterprise. Active exploitation reported; upgrade to 10.0.7 or 10.2.4.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| splunk | 10.0.0 | 10.0.7 | vulnerable |
| splunk | 10.2.0 | 10.2.4 | vulnerable |
Download and install the latest security updates provided by Splunk. Ensure that all Splunk Enterprise deployments, including indexers and search heads, are running patched software versions to close the authentication gap in the sidecar service.
Upgrade Splunk Enterprise 10.0.x versions to 10.0.7 or later, and 10.2.x versions to 10.2.4 or later. Note that versions 9.4 and earlier are not affected by this specific vulnerability.
If an immediate upgrade is not feasible, mitigate the risk by disabling the PostgreSQL sidecar service as per vendor instructions. Additionally, use network firewalls or Access Control Lists (ACLs) to restrict access to Splunk service endpoints to trusted internal IP addresses only.
Audit system and application logs for unauthorized file creation or truncation events. Specifically, monitor the PostgreSQL sidecar service logs for requests originating from unauthenticated or unexpected network sources.
To detect potential exploitation, monitor Splunk internal logs and host-level audit logs (such as auditd on Linux) for unexpected file system modifications originating from the Splunk service account. Look for network traffic patterns involving unauthenticated connections to the PostgreSQL sidecar service port. Security teams should alert on any unauthorized file truncation or the presence of unexpected new files in the Splunk installation directory, which may indicate an attacker attempting to overwrite configurations or binaries.
Experience superior visibility and a simpler approach to cyber risk management