CVE-2026-20253: The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. in Splunk Splunk Enterprise
Splunk Enterprise versions 10.2 prior to 10.2.4 and 10.0 prior to 10.0.7 contain a critical vulnerability where the PostgreSQL sidecar service endpoint does not require authentication. This allows unauthenticated network users to create or truncate arbitrary files. Versions 9.4 and earlier are not affected. Disabling the PostgreSQL sidecar service can mitigate the issue if immediate upgrading is not possible.
AI Analysis
Technical Summary
CVE-2026-20253 affects Splunk Enterprise versions 10.2 before 10.2.4 and 10.0 before 10.0.7. The vulnerability arises because the PostgreSQL sidecar service endpoint lacks authentication controls, enabling unauthenticated users with network access to perform file creation or truncation operations arbitrarily. This can lead to complete compromise of confidentiality, integrity, and availability of affected systems. Versions 9.4 and earlier are not vulnerable. The vulnerability has a CVSS 3.1 base score of 9.8, indicating critical severity.
Potential Impact
An unauthenticated attacker with network access to the PostgreSQL sidecar service endpoint can create or truncate arbitrary files on the affected Splunk Enterprise systems. This results in full compromise of confidentiality, integrity, and availability, potentially allowing data destruction or unauthorized data manipulation.
Mitigation Recommendations
A fixed version is available starting from Splunk Enterprise 10.2.4 and 10.0.7. Users should upgrade to these or later versions to remediate the vulnerability. If immediate upgrade is not feasible, disabling the PostgreSQL sidecar service effectively mitigates the risk by preventing unauthenticated access to the vulnerable endpoint.
CVE-2026-20253: The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. in Splunk Splunk Enterprise
Description
Splunk Enterprise versions 10.2 prior to 10.2.4 and 10.0 prior to 10.0.7 contain a critical vulnerability where the PostgreSQL sidecar service endpoint does not require authentication. This allows unauthenticated network users to create or truncate arbitrary files. Versions 9.4 and earlier are not affected. Disabling the PostgreSQL sidecar service can mitigate the issue if immediate upgrading is not possible.
CVSS v3.1
Score 9.8critical
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-20253 affects Splunk Enterprise versions 10.2 before 10.2.4 and 10.0 before 10.0.7. The vulnerability arises because the PostgreSQL sidecar service endpoint lacks authentication controls, enabling unauthenticated users with network access to perform file creation or truncation operations arbitrarily. This can lead to complete compromise of confidentiality, integrity, and availability of affected systems. Versions 9.4 and earlier are not vulnerable. The vulnerability has a CVSS 3.1 base score of 9.8, indicating critical severity.
Potential Impact
An unauthenticated attacker with network access to the PostgreSQL sidecar service endpoint can create or truncate arbitrary files on the affected Splunk Enterprise systems. This results in full compromise of confidentiality, integrity, and availability, potentially allowing data destruction or unauthorized data manipulation.
Mitigation Recommendations
A fixed version is available starting from Splunk Enterprise 10.2.4 and 10.0.7. Users should upgrade to these or later versions to remediate the vulnerability. If immediate upgrade is not feasible, disabling the PostgreSQL sidecar service effectively mitigates the risk by preventing unauthenticated access to the vulnerable endpoint.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- cisco
- Date Reserved
- 2025-10-08T11:59:15.401Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a29aa2b1a4077f7803bb96f
Added to database: 06/10/2026, 18:17:15 UTC
Last enriched: 06/25/2026, 21:33:09 UTC
Last updated: 07/31/2026, 19:22:57 UTC
Views: 444
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.