Splunk patches critical Splunk Enterprise flaw CVE-2026-20253 that lets unauthenticated attackers create or overwrite files

Splunk released security updates for a critical flaw in Splunk Enterprise that could let attackers on the network create or modify files without logging in. The bug, CVE-2026-20253, has a CVSS score of 9.8 and affects a PostgreSQL sidecar service endpoint that lacks authentication; Splunk also fixed three high-severity Splunk Enterprise bugs tied to remote code execution, server-side request forgery (making the server send attacker-chosen requests), and cross-site scripting, plus additional issues in Splunk SOAR and third-party components.
Why it matters: Organizations running Splunk Enterprise or Splunk SOAR should treat this as a high-priority update because the most severe issue is remotely reachable without authentication. Admins should patch quickly and review exposure of Splunk services to internal and external networks.

Sources

CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
Sergiu Gatlan 2026.06.19 97% relevant
This updates the same CVE-2026-20253 event with materially new information: Splunk says it has seen limited in-the-wild exploitation, and CISA has added the flaw to its actively exploited workflow for federal agencies under BOD 26-04 with a Sunday remediation deadline.
Splunk Enterprise Vulnerability Exploited in Attacks Days After Disclosure
Eduard Kovacs 2026.06.19 96% relevant
This article updates the same CVE-2026-20253 event with confirmation that the flaw is now being exploited in the wild, notes that WatchTowr published PoC details shortly after disclosure, and adds that CISA placed it in KEV with a June 21 deadline for federal agencies.
Atlassian, Splunk Patch Critical Vulnerabilities
Ionut Arghire 2026.06.18 63% relevant
This adds a separate June Splunk security update: Splunk fixed CVE-2026-20266, a critical OS command injection in the AI Toolkit app for Splunk Enterprise, plus CVE-2026-20265, and advises upgrading to AI Toolkit 5.7.4 or uninstalling the app if upgrading is not possible.
Splunk, Palo Alto Networks Patch Severe Vulnerabilities
Ionut Arghire 2026.06.11 100% relevant
This article establishes a discrete patch event centered on Splunk's June 2026 advisories, led by critical CVE-2026-20253 in Splunk Enterprise.
← Back to all stories