<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Splunk Enterprise Hit by Critical Pre-Auth RCE Vulnerability Scoring 9.8 CVSS

Critical Splunk vulnerability CVE-2026-20253 allows remote code execution. Patch now to secure AWS deployments from attacks.
Content Team

A severe vulnerability chain in Splunk Enterprise is letting unauthenticated attackers execute remote code, no login required. Tracked as CVE-2026-20253 with a CVSS score of 9.8, the flaw targets the PostgreSQL Sidecar Service in Splunk Enterprise 10.0.0–10.0.6 and 10.2.0–10.2.3. Versions 9.4 and earlier, and Splunk Cloud Platform, are not affected.

The sidecar is active by default on AWS deployments, making those installations immediately exposed; on-premises deployments don't enable it by default. Researchers at watchTowr Labs found attackers can send crafted HTTP requests to internal API endpoints, manipulate file paths, inject malicious database connections, and ultimately overwrite Python scripts to run arbitrary commands. A non-weaponised proof of concept is already public.

Splunk has patched it in 10.0.7 and 10.2.4 — AWS users should prioritise updating immediately. If you can't patch yet, the sidecar can be disabled with [postgres] disabled = true in server.conf, but that breaks Edge Processor, OpAmp and SPL2 pipelines, so check what you're running first. Either way, Splunk Web on port 8000 shouldn't be reachable from the internet.

Updated 12 Aug 2026: Splunk updated its advisory on 18 June to warn of active exploitation in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo