Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
ID: e38f16d5-2cb8-5a84-9b61-80ac022d812b
STIX ID: report--e38f16d5-2cb8-5a84-9b61-80ac022d812b
Feed Name: The Hacker News
Splunk Enterprise CVE-2026-20253 (CVSS 9.8) is a critical unauthenticated vulnerability in the PostgreSQL sidecar service that allows attackers to create/write arbitrary files and potentially achieve pre-authenticated remote code execution via the /v1/postgres/recovery/backup and /restore endpoints; fixes are available in Splunk Enterprise 10.0.7 and 10.2.4 (Splunk Cloud not affected), and technical exploit details have been published though no active exploitation has been observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
