CVE-2026-20253: Critical Splunk Enterprise RCE Vulnerability Under Active Attack
A CVSS 9.8 critical vulnerability in Splunk Enterprise allows unauthenticated remote code execution. CISA confirms active exploitation. Patch immediately to versions 10.2.4 or 10.0.7.
The Vulnerability
**CVE-2026-20253** is a critical (CVSS 9.8) missing authentication vulnerability in Splunk Enterprise that allows unauthenticated remote code execution. The flaw affects the PostgreSQL sidecar service endpoint, which accepts requests without any authentication.
Affected Versions
|----------------|------------------|---------------|
**Note**: Splunk Cloud Platform is NOT affected — it doesn't use the PostgreSQL sidecar architecture.
Timeline of Exploitation
|------|-------|
The patch-to-exploitation window was just **five days** — and public PoC code was available from day two.
How the Attack Works
The vulnerability resides in the PostgreSQL sidecar service that supports Edge Processor, OpAmp, and SPL2 data pipelines. The attack chain:
1. **Attacker sends unauthenticated request** to the sidecar endpoint
2. **Connection string injection** redirects PostgreSQL tools to attacker-controlled server
3. **PostgreSQL's lo_export function** overwrites Python scripts in Splunk directories
4. **When Splunk re-runs scripts**, attacker code executes with full process privileges
The sidecar accepts any credentials — including empty strings — making authentication completely bypassed.
What You Should Do
Immediate Actions
1. **Upgrade to patched versions** (10.2.4, 10.0.7, or 10.4.0)
2. **If patching is delayed**, disable the PostgreSQL sidecar service (temporarily)
3. **Check for indicators of compromise**:
Detection Check
Send a request to the vulnerable endpoint:
Impact Assessment
Over **1,400 internet-exposed Splunk instances** are tracked by Shadowserver, with more than 950 in North America. If your organization runs Splunk Enterprise on-premises and faces the internet, you're a target.
Check Your Domain
Scan your domain for exposed services and security misconfigurations.
[Free security scan at Vaarta.space](https://vaarta.space)
Related Articles
Oracle PeopleSoft Zero-Day: ShinyHunters Compromises 300+ Instances Across 100 Organizations
ShinyHunters exploited CVE-2026-35273, a CVSS 9.8 unauthenticated RCE in Oracle PeopleSoft, to compromise over 300 instances across 100+ organizations including universities and enterprises.
2026-05-12Spring4Shell CVE-2022-22965 — RCE Vulnerability Explained | Vaarta
Complete analysis of Spring4Shell (CVE-2022-22965). How the RCE exploit works, affected versions, detection methods, and remediation steps for Java apps.
2026-06-24Cisco SD-WAN Zero-Day Exploited: Hackers Gained Root Access at Major Communications Provider
Mandiant revealed that attackers exploited a previously unknown Cisco vulnerability to gain root-level access at a communications service provider, potentially intercepting all internal traffic.
Ready to check your domain security?
Run a free scan to identify potential vulnerabilities.
Start Free Scan