logo

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

ID: e38f16d5-2cb8-5a84-9b61-80ac022d812b

STIX ID: report--e38f16d5-2cb8-5a84-9b61-80ac022d812b

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-13

Date Updated: 2026-06-13

Author: [email protected] (The Hacker News)

...
...

Splunk Enterprise CVE-2026-20253 (CVSS 9.8) is a critical unauthenticated vulnerability in the PostgreSQL sidecar service that allows attackers to create/write arbitrary files and potentially achieve pre-authenticated remote code execution via the /v1/postgres/recovery/backup and /restore endpoints; fixes are available in Splunk Enterprise 10.0.7 and 10.2.4 (Splunk Cloud not affected), and technical exploit details have been published though no active exploitation has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.