CVE-2026-20253

Modified
Published: 10 Jun 2026, 17:16
Last modified:19 Jun 2026, 03:55

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
10.04% MEDIUM
10% probability +8.30%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

10 Jun 2026, 17:16
Published
Vulnerability first disclosed
18 Jun 2026, 00:00
Added to CISA KEV
Splunk Enterprise Missing Authentication for Critical Function Vulnerability
19 Jun 2026, 03:55
Last Modified
Vulnerability information updated
21 Jun 2026, 00:00
CISA Remediation Due
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Description

In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 10.04% Percentile: 95%

Techniques & Countermeasures

  • CWE-306Missing Authentication for Critical Function

    The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Affected Systems

  • splunksplunk

    ≥ 10.0.0, < 10.0.7 | ≥ 10.2.0, < 10.2.4

  • splunksplunk_cloud_platform

    ≥ 10.4.2604, < 10.4.2604.3 | ≥ 10.2.2510, < 10.2.2510.14

  • splunksplunk enterprise

    ≥ 10.2, < 10.2.4 | ≥ 10.0, < 10.0.7

References (3)