Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-20253

Published 2026-06-10
Updated 2 months ago
Vendor/s
Splunk
Product/s
Enterprise
Version/s
10.0.0 > 10.0.7
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

Critical CVE-2026-20253 (CVSS 9.8) allows unauthenticated file manipulation in Splunk Enterprise. Active exploitation reported; upgrade to 10.0.7 or 10.2.4.

CPE

Splunk logo
Splunk
Product Version Start Version End (excl.) Status
splunk 10.0.0 10.0.7 vulnerable
splunk 10.2.0 10.2.4 vulnerable

Related weakness (CWE)

CWE-306

Remediation plan

1

Apply official patches

Download and install the latest security updates provided by Splunk. Ensure that all Splunk Enterprise deployments, including indexers and search heads, are running patched software versions to close the authentication gap in the sidecar service.

2

Update affected systems

Upgrade Splunk Enterprise 10.0.x versions to 10.0.7 or later, and 10.2.x versions to 10.2.4 or later. Note that versions 9.4 and earlier are not affected by this specific vulnerability.

3

Restrict access

If an immediate upgrade is not feasible, mitigate the risk by disabling the PostgreSQL sidecar service as per vendor instructions. Additionally, use network firewalls or Access Control Lists (ACLs) to restrict access to Splunk service endpoints to trusted internal IP addresses only.

4

Monitor for exploitation

Audit system and application logs for unauthorized file creation or truncation events. Specifically, monitor the PostgreSQL sidecar service logs for requests originating from unauthenticated or unexpected network sources.

Detection Guidance

To detect potential exploitation, monitor Splunk internal logs and host-level audit logs (such as auditd on Linux) for unexpected file system modifications originating from the Splunk service account. Look for network traffic patterns involving unauthenticated connections to the PostgreSQL sidecar service port. Security teams should alert on any unauthorized file truncation or the presence of unexpected new files in the Splunk installation directory, which may indicate an attacker attempting to overwrite configurations or binaries.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management