Knox CVE Database
/
CVE-2026-20253
Critical
9.8

CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

Added to the CISA KEV catalog:
June 18, 2026

Overview

Splunk Enterprise versions 10.0.0 through 10.0.6 and 10.2.0 through 10.2.3 expose a PostgreSQL sidecar service endpoint that accepts file operation requests without any authentication. An unauthenticated, network-reachable attacker can send crafted requests to this endpoint to create or truncate arbitrary files on the host filesystem. Splunk's PSIRT confirmed limited exploitation in June 2026. The sidecar service is enabled by default on AWS deployments, making those instances immediately exposed.

Vulnerability details

Affected vendor
Splunk
Affected product
Enterprise
Weakness type (CWE)
CWE-306

CWE-306 describes a critical function exposed without an authentication gate. In this case, the PostgreSQL sidecar service introduced in Splunk Enterprise version 10 exposes a network endpoint that performs host filesystem operations. Because the service applies no credential check before processing requests, any caller that can reach the endpoint is treated as authorized. The service binds to the loopback interface by default, but on AWS deployments it is installed and active out of the box, and the watchTowr research indicates the loopback binding does not reliably prevent external reach under certain deployment conditions.


An attacker who can reach the sidecar endpoint sends crafted requests specifying target file paths and file operation parameters, creating new files or truncating existing ones on the Splunk host without supplying any credentials. The vendor advisory characterizes the impact as arbitrary file creation and truncation. The watchTowr research, published alongside the advisory, characterizes the file-write primitive as sufficient to achieve pre-authentication remote code execution, though the precise chain from file write to code execution is not confirmed in the vendor advisory. The precondition is that the PostgreSQL sidecar service must be installed and reachable, a condition met by default on AWS-hosted deployments of affected versions.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Monitor Splunk host audit logs for unexpected file creation or truncation events in directories outside normal Splunk write paths, particularly those initiated by the splunk-postgres process rather than splunkd or a logged-in user session.
  • Review network flow logs for connections to the sidecar service ports (5435 and the secondary management port observed in research) originating from sources other than localhost or known Splunk peer addresses, which would indicate external reach to a loopback-bound service.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see References) guidance and CISA’s “Forensics Triage Requirements” (see References). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
June 21, 2026

Additional hardening

  • Upgrade Splunk Enterprise to 10.2.4 or later on the 10.2 release line, or to 10.0.7 or later on the 10.0 release line. See the vendor advisory in References for the full version matrix.
  • If immediate upgrade is not possible, disable the PostgreSQL sidecar by adding a [postgres] stanza with disabled = true to $SPLUNK_HOME/etc/system/local/server.conf and restarting Splunk. Do not apply this workaround on instances running Edge Processor, OpAmp, or SPL2 data pipelines.
  • Restrict network access to Splunk Enterprise hosts at the perimeter and host firewall level so the sidecar service ports are not reachable from untrusted network segments, reducing exposure even when the service is active.
  • Audit AWS-hosted Splunk deployments first, as the PostgreSQL sidecar is installed and active by default in that environment, making those instances exposed without additional configuration steps.

Key dates

Published (NVD)
June 10, 2026
Added to CISA KEV
June 18, 2026
Remediation deadline
June 21, 2026
Last updated
July 23, 2026

References

Frequently asked questions

Does CVE-2026-20253 affect my FedRAMP authorization?

If Splunk Enterprise runs inside your authorization boundary, yes. CVE-2026-20253 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, and its remediation deadline of June 21, 2026 has already passed. For a FedRAMP-authorized service, an unpatched KEV in your boundary is an assessor finding. An overdue one is visible to your assessor and sponsoring agency right now. Your options are to remediate it or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-20253?

Knox does not patch your Splunk Enterprise deployment. Under the FedRAMP shared-responsibility model, remediating CVE-2026-20253 is your obligation. What Knox provides is the pre-authorized, single-tenant boundary to carry out that remediation in, along with continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you have to handle alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including CVE-2026-20253. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you a materially shorter window between disclosure and awareness.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-20253's remediation deadline of June 21, 2026 has passed. What happens now?

An unremediated CVE-2026-20253 is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing out the finding now and documenting the circumstances of the delay is what keeps your authorization intact and the agency relationship on solid footing.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting