CVE-2026-20253
CRITICAL · 9.8 KEV EPSS 88.2%KEV-listed, active exploitation confirmed by vendor, urgent patching underway, defender triage happening now.
What: Unauthenticated file creation/truncation in Splunk Enterprise and Cloud Platform via unprotected PostgreSQL sidecar endpoint. CVSS 9.8 CRITICAL, EPSS 0.017.
Why it matters: KEV-listed as of 18 June; Splunk confirmed limited in-the-wild exploitation; CISA mandated federal agencies patch by 21 June (tomorrow). No credential required to trigger; compromised SIEM silences downstream alerts, making this operationally catastrophic for defenders.
Where it's seen: Mainstream security news, CTI call-outs, and urgent vendor patching directives. Posts emphasize KEV listing, tight deadline, and active exploitation confirmation from Splunk PSIRT.
RISK: CRITICAL — Unauthenticated, KEV-listed, limited exploitation confirmed, 9.8 CVSS, federal deadline.
Description
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High