CVE-2026-20253
Vulnerability Summary
Timeline
Description
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 10.04%• Percentile: 95%
Techniques & Countermeasures
- CWE-306•Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Affected Systems
- splunk•splunk
≥ 10.0.0, < 10.0.7 | ≥ 10.2.0, < 10.2.4
- splunk•splunk_cloud_platform
≥ 10.4.2604, < 10.4.2604.3 | ≥ 10.2.2510, < 10.2.2510.14
- splunk•splunk enterprise
≥ 10.2, < 10.2.4 | ≥ 10.0, < 10.0.7