CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6244

As cited

Copy frozen at (site build).

vulnerabilities

Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253)

Splunk disclosed CVE-2026-20253, a critical unauthenticated remote code execution vulnerability in Splunk Enterprise with a CVSS score of 9.8, caused by missing authentication on a PostgreSQL sidecar recovery endpoint exposed through Splunk Web. Active exploitation was confirmed on June 18, 2026, and the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 21, 2026. An attacker can chain path traversal, connection string injection, and credential theft to achieve arbitrary file write and ultimately execute code under the Splunk service account, potentially tampering with logs, harvesting credentials, and pivoting into internal infrastructure.

Why it matters: Organizations running Splunk Enterprise versions 10.0.x (prior to 10.0.7) or 10.2.x (prior to 10.2.4) face immediate active exploitation risk; federal agencies must remediate by the BOD 26-04 deadline, and all practitioners should prioritize upgrading or implementing network restrictions to prevent unauthenticated access to Splunk Web on port 8000.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253)

Splunk disclosed CVE-2026-20253, a critical unauthenticated remote code execution vulnerability in Splunk Enterprise with a CVSS score of 9.8, caused by missing authentication on a PostgreSQL sidecar recovery endpoint exposed through Splunk Web. Active exploitation was confirmed on June 18, 2026, and the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 21, 2026. An attacker can chain path traversal, connection string injection, and credential theft to achieve arbitrary file write and ultimately execute code under the Splunk service account, potentially tampering with logs, harvesting credentials, and pivoting into internal infrastructure.

Why it matters: Organizations running Splunk Enterprise versions 10.0.x (prior to 10.0.7) or 10.2.x (prior to 10.2.4) face immediate active exploitation risk; federal agencies must remediate by the BOD 26-04 deadline, and all practitioners should prioritize upgrading or implementing network restrictions to prevent unauthenticated access to Splunk Web on port 8000.

VendorsAmazon Web ServicesSplunk
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary