CVE-2026-20253: Splunk Enterprise's Unauthenticated Arbitrary File Write Flaw
Technical breakdown of the unauthenticated PostgreSQL sidecar file write/truncation flaw in Splunk Enterprise.
An unauthenticated arbitrary file write and truncation flaw in Splunk Enterprise's PostgreSQL sidecar daemon allowed remote attackers to corrupt logs, disrupt SIEM operations, and facilitate secondary attack chains.
CVE-2026-20253 (CWE-73: External Control of File Name or Path)
Severity: High (CVSS 8.1 — Remote Arbitrary File Creation/Truncation)
Status: ⚠️ CISA KEV Catalog Added (Active exploitation observed)
Fixed Versions: Splunk Enterprise 10.2.4 / 10.0.7
What's Affected
Splunk Enterprise versions 10.2.0 – 10.2.3 and 10.0.0 – 10.0.6 when the PostgreSQL sidecar service is network-reachable.
The Vulnerability
The PostgreSQL sidecar service supporting Edge Processor and SPL2 features exposed an unauthenticated endpoint capable of invoking file write and truncation operations directly on the filesystem.