Splunk has released emergency security updates to address a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to achieve remote code execution on vulnerable systems. The flaw, designated CVE-2026-20253, carries a CVSS score of 9.8, placing it among the most severe classes of enterprise software vulnerabilities. The issue resides in the PostgreSQL sidecar service endpoint, which lacks authentication controls and exposes unauthenticated file operations to any network-reachable user.
What Is CVE-2026-20253 and Who Is Affected
Tracked as CVE-2026-20253 with a CVSS score of 9.8, the vulnerability affects Splunk Enterprise versions below 10.2.4 and 10.0.7. Specifically, versions 10.0.0 through 10.0.6 and 10.2.0 through 10.2.3 are vulnerable. Splunk Enterprise 10.4 is not affected. Splunk Cloud is also not impacted because it does not use PostgreSQL sidecars. The flaw enables an unauthenticated user to create or truncate arbitrary files on the target system by invoking file operations through the PostgreSQL sidecar service endpoint without any credentials.
How the Splunk RCE Attack Chain Works
Security researchers Piotr Bazydlo and Yordan Ganchev of watchTowr Labs released detailed technical analysis of CVE-2026-20253, demonstrating a complete pre-authenticated remote code execution chain. The attack leverages two specific endpoints: /v1/postgres/recovery/backup and /v1/postgres/recovery/restore.
The exploitation proceeds in three stages. First, the attacker connects to a PostgreSQL database they control and uses the /backup endpoint to dump its contents into an arbitrary file on the Splunk system. Second, the attacker uses the /restore endpoint to load that malicious database dump into the local PostgreSQL instance, supplying a passfile argument that points to the .pgpass file containing the password for the postgres_admin user. Third, SQL queries embedded in the database dump execute during the restoration process. The attacker defines a new PostgreSQL function that uses lo_export — a built-in function for extracting BLOBs to the file system — to write attacker-controlled content to a file.
Once arbitrary file write is achieved, the attacker escalates to remote code execution by overwriting a Python script that Splunk executes frequently, such as /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py, injecting malicious payload code.
What Affected Organizations Should Do Now
Splunk has addressed the vulnerability in versions 10.0.7 and 10.2.4. Organizations running any affected version should update immediately. There is no evidence of active exploitation in the wild at the time of disclosure, but the public availability of detailed exploit technicals significantly increases the risk of opportunistic attacks. Security teams should also audit access logs for the PostgreSQL sidecar endpoints, review any unexpected file modifications on Splunk servers, and monitor for unauthorized outbound database connections. As an immediate security measure, if immediate patching is not possible, restrict network access to the PostgreSQL sidecar service endpoints to only trusted internal hosts using firewall rules or network segmentation until the update can be applied. This vulnerability underscores the critical importance of authentication controls on internal service endpoints, particularly in enterprise log management and analysis platforms that hold sensitive operational data.