Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)
ID: 58dd15c6-ac77-573c-8a51-81c2f1deb636
STIX ID: report--58dd15c6-ac77-573c-8a51-81c2f1deb636
Feed Name: Help Net Security
Critical Splunk Enterprise vulnerability CVE-2026-20253 permits unauthenticated file operations via the PostgreSQL sidecar service, enabling potential full compromise of Splunk deployments; exploitation in the wild has been confirmed, vendor patches (10.4.0, 10.2.4, 10.0.7+) and mitigations (including disabling the sidecar) are available, and organizations should patch and search for IOCs such as path traversal requests, unexpected pg_dump/pg_restore activity, database dump files in unusual locations, and outbound connections to unknown PostgreSQL servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
