Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases
ID: b003affd-14ee-586b-82b1-8678d875bd7e
STIX ID: report--b003affd-14ee-586b-82b1-8678d875bd7e
Feed Name: GBHackers
**Executive summary:** A critical pre-authentication RCE (CVE-2026-20253, CVSS 9.8) affects Splunk Enterprise 10.x+ via unauthenticated PostgreSQL Sidecar Service endpoints (/v1/postgres/recovery/backup and /restore). Attackers can abuse path traversal and libpq connection-string injection to redirect pg_dump to attacker-controlled hosts, leverage an exposed .pgpass to authenticate, restore a malicious dump to perform lo_export arbitrary file writes, and overwrite a Splunk Python script to achieve code execution as the splunk user; AWS-hosted deployments with the Sidecar enabled by default are particularly at risk, and Splunk patches and detection artifacts are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
