CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials. Splunk Enterprise versions 9.4 and earlier are not affected. If you cannot immediately upgrade to a fixed version, you can mitigate this vulnerability by disabling the PostgreSQL sidecar service.
Other sources
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.4 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.7 - Configuration
If you cannot immediately upgrade to a fixed version, mitigate by disabling the PostgreSQL sidecar service so the unauthenticated PostgreSQL sidecar endpoint cannot be used to create or truncate arbitrary files.
PostgreSQL sidecar service (Splunk Enterprise) authentication/sidecar service endpoint access = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20253?
CVE-2026-20253 has a critical severity rating of 9.8.
How do I fix CVE-2026-20253?
To fix CVE-2026-20253, upgrade to Splunk Enterprise version 10.2.4 or 10.0.7 or Splunk Cloud Platform version 10.4.2604.3 or 10.2.2510.14.
Who is affected by CVE-2026-20253?
CVE-2026-20253 affects users of Splunk Enterprise versions below 10.2.4 and 10.0.7, as well as Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14.
What type of vulnerability is CVE-2026-20253?
CVE-2026-20253 is an unauthenticated arbitrary file creation and truncation vulnerability.
What can an attacker do with CVE-2026-20253?
An attacker can create or truncate arbitrary files through the PostgreSQL sidecar service endpoint if they exploit CVE-2026-20253.