CVE-2026-20253 PUBLISHED

Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise

Assigner: cisco
Reserved: 08.10.2025 Published: 10.06.2026 Updated: 11.06.2026

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Splunk
Product Splunk Enterprise
Versions
  • affected from 10.2 to 10.2.4 (excl.)
  • affected from 10.0 to 10.0.7 (excl.)
Vendor Splunk
Product Splunk Cloud Platform
Versions
  • affected from 10.4.2604 to 10.4.2604.3 (excl.)
  • affected from 10.2.2510 to 10.2.2510.14 (excl.)

Credits

  • Alex Hordijk (hordalex)

References

Problem Types

  • The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. cwe