<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Splunk Enterprise Hit by Critical Pre-Auth RCE Vulnerability Scoring 9.8 CVSS

Critical Splunk vulnerability CVE-2026-20253 allows remote code execution. Patch now to secure AWS deployments from attacks.
Content Team

A severe vulnerability chain in Splunk Enterprise is letting unauthenticated attackers execute remote code, no login required. Tracked as CVE-2026-20253 with a CVSS score of 9.8, the flaw targets the PostgreSQL Sidecar Service introduced in Splunk Enterprise 10 and later.

The service is active by default on AWS deployments, making cloud installations immediately exposed. Researchers at watchTowr Labs found attackers can send crafted HTTP requests to internal API endpoints, manipulate file paths, inject malicious database connections, and ultimately overwrite Python scripts to run arbitrary commands.

Splunk has released a patch — AWS users should prioritize updating immediately.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo