As cited
Copy frozen at (site build).
vulnerabilities
Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253)
Splunk disclosed CVE-2026-20253, a critical unauthenticated remote code execution vulnerability in Splunk Enterprise with a CVSS score of 9.8, caused by missing authentication on a PostgreSQL sidecar recovery endpoint exposed through Splunk Web. Active exploitation was confirmed on June 18, 2026, and the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 21, 2026. An attacker can chain path traversal, connection string injection, and credential theft to achieve arbitrary file write and ultimately execute code under the Splunk service account, potentially tampering with logs, harvesting credentials, and pivoting into internal infrastructure.
Why it matters: Organizations running Splunk Enterprise versions 10.0.x (prior to 10.0.7) or 10.2.x (prior to 10.2.4) face immediate active exploitation risk; federal agencies must remediate by the BOD 26-04 deadline, and all practitioners should prioritize upgrading or implementing network restrictions to prevent unauthenticated access to Splunk Web on port 8000.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253)
Splunk disclosed CVE-2026-20253, a critical unauthenticated remote code execution vulnerability in Splunk Enterprise with a CVSS score of 9.8, caused by missing authentication on a PostgreSQL sidecar recovery endpoint exposed through Splunk Web. Active exploitation was confirmed on June 18, 2026, and the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog with a federal remediation deadline of June 21, 2026. An attacker can chain path traversal, connection string injection, and credential theft to achieve arbitrary file write and ultimately execute code under the Splunk service account, potentially tampering with logs, harvesting credentials, and pivoting into internal infrastructure.
Why it matters: Organizations running Splunk Enterprise versions 10.0.x (prior to 10.0.7) or 10.2.x (prior to 10.2.4) face immediate active exploitation risk; federal agencies must remediate by the BOD 26-04 deadline, and all practitioners should prioritize upgrading or implementing network restrictions to prevent unauthenticated access to Splunk Web on port 8000.
- Source published
- First seen by Cybersecurity Tracker