67
Technology4h 6m ago

Splunk published an advisory for CVE-2026-20253, a pre-authentication Remote Code Execution vulnerability in Splunk Enterprise.

Archive Window: 30 Days Left

not specified

Who
Splunk, watchTowr Labs
What
Splunk published an advisory for CVE-2026-20253, a pre-authentication Remote Code Execution vulnerability in Splunk Enterprise.
When
Fri, 12 Jun 2026 20:37:11 GMT · 4h 6m ago
Where
not specified ·
Why
The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.
The Frontline Impact

How this affects you

This vulnerability allows remote code execution (RCE) without authentication in Splunk Enterprise, particularly affecting Splunk Enterprise on AWS, which is vulnerable by default. This could lead to unauthorized access and control of systems running Splunk.

Story chain

6 events in this thread

Verified Sources & Citations