logo

Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases

ID: b003affd-14ee-586b-82b1-8678d875bd7e

STIX ID: report--b003affd-14ee-586b-82b1-8678d875bd7e

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-13

Date Updated: 2026-06-13

Author: Eswar

...
...

**Executive summary:** A critical pre-authentication RCE (CVE-2026-20253, CVSS 9.8) affects Splunk Enterprise 10.x+ via unauthenticated PostgreSQL Sidecar Service endpoints (/v1/postgres/recovery/backup and /restore). Attackers can abuse path traversal and libpq connection-string injection to redirect pg_dump to attacker-controlled hosts, leverage an exposed .pgpass to authenticate, restore a malicious dump to perform lo_export arbitrary file writes, and overwrite a Splunk Python script to achieve code execution as the splunk user; AWS-hosted deployments with the Sidecar enabled by default are particularly at risk, and Splunk patches and detection artifacts are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.