LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 18, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 21, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-20253 to its Known Exploited Vulnerabilities catalog on Jun 18, 2026, with a federal patch deadline of Jun 21, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar…

Splunk Enterprise contains a missing authentication vulnerability that lets an unauthenticated user reach a PostgreSQL sidecar service endpoint and create or truncate arbitrary files. The issue is tracked as CVE-2026-20253 and is classified under CWE-306. Organizations that rely on Splunk for centralized logging and security monitoring should determine whether their deployments expose the affected component.

How it works

The weakness is missing authentication for a critical function. An attacker can send requests directly to the PostgreSQL sidecar service endpoint without presenting credentials. Because the endpoint lacks an authentication check, the request succeeds and the server performs file operations on behalf of the unauthenticated caller.

Am I affected? How to find it in your systems

Splunk Enterprise deployments that include the PostgreSQL sidecar service are potentially exposed. Inventory all Splunk search heads, indexers, and clustered nodes to identify where the sidecar component is present. Review configuration files and service definitions that reference the PostgreSQL sidecar endpoint. Check installed Splunk versions and any custom integrations that expose the endpoint to untrusted networks. Examine logs for unexpected file operations or unauthenticated connections to the sidecar port; absence of such logs does not rule out prior activity.

How to remediate

Apply the vendor-supplied update or configuration change that restores authentication on the PostgreSQL sidecar endpoint. Follow the instructions published in the official Splunk advisory. Ensure the change is deployed consistently across all search heads, indexers, and forwarders that run the sidecar service. After patching, verify that the endpoint now requires authentication and that file-creation privileges are restricted to authorized accounts.

If you can't patch immediately

Until the vendor fix can be applied, reduce the attack surface by restricting network access to the PostgreSQL sidecar endpoint through firewall rules or network segmentation. Disable or remove the sidecar service where it is not required. Monitor authentication and file-system logs for anomalous activity on Splunk hosts. For cloud-hosted instances, follow the additional guidance in CISA BOD 26-04; if mitigations cannot be implemented, discontinue use of the affected deployment.

If your data may have been exposed

Successful exploitation can alter files on Splunk hosts and may indicate broader compromise. Review file-integrity monitoring data and Splunk internal logs for unexpected changes. Organizations can run a free exposure scan of their email addresses against known breach data to check for related incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSplunk · Enterprise
WeaknessCWE-306
Added to CISA KEVJun 18, 2026
Federal patch deadlineJun 21, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities