Summary

CVE-2026-20253, a critical unauthenticated remote code execution vulnerability in Splunk Enterprise, is being actively exploited in the wild. The flaw, carrying a CVSS score of 9.8, exists in the PostgreSQL sidecar service that ships with Splunk Enterprise versions 10.0 and 10.2. The endpoint lacks authentication controls entirely, allowing any network-reachable attacker to perform arbitrary file operations without credentials.

Researchers demonstrated that the file-write primitive can be chained with PostgreSQL’s lo_export function to write and execute malicious scripts, achieving full pre-authenticated RCE as the Splunk user. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, and Splunk’s PSIRT has confirmed limited exploitation in the wild.

Affected versions include Splunk Enterprise 10.2 below 10.2.4 and 10.0 below 10.0.7. Splunk Enterprise 9.4 and earlier, as well as Splunk Cloud Platform, are not affected. Organizations that cannot immediately upgrade can mitigate by disabling the PostgreSQL sidecar service, though this impacts some functionality.

Source

Commentary

There’s a special kind of irony in your SIEM — the system that’s supposed to detect breaches — being the breach vector. Splunk Enterprise sits at the heart of most enterprise SOCs, with access to security logs, credentials, and network visibility that attackers dream about. Compromising Splunk doesn’t just give you a foothold; it gives you the keys to the entire security monitoring apparatus.

The root cause here — an unauthenticated PostgreSQL service exposed to the network — is the kind of basic architectural flaw that shouldn’t ship in a security product in 2026. If you’re running affected versions, patch now. If you can’t patch now, isolate the management interface and disable the PostgreSQL sidecar. Your SIEM should not be the weakest link in your security chain.

By Allan