logo

CVE-2026-20253: Splunk Enterprise Pre-Authentication Remote Code Execution

ID: 3ef40434-1b37-592f-9751-42155a72e673

STIX ID: report--3ef40434-1b37-592f-9751-42155a72e673

Feed Name: Resecurity

Threat Score
90/100

Date Published: 2026-06-16

Date Updated: 2026-07-27

...
...

Resecurity reports CVE-2026-20253, a critical pre-authentication RCE in Splunk Enterprise's PostgreSQL Sidecar Service that allows unauthenticated attackers to abuse exposed backup/restore endpoints to perform arbitrary file writes, force Splunk to connect to attacker-controlled PostgreSQL servers, and execute attacker-controlled SQL during restores — ultimately enabling full system compromise; the advisory includes affected versions, a detailed attack chain and proof-of-concept indicators, detection guidance (including a Nuclei template), and recommended mitigations such as applying vendor patches, restricting access, monitoring recovery endpoints, and rotating credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.