# Splunk Enterprise Flaw Exploited in Active Attacks—CISA Orders Federal Patch Within 72 Hours


A critical remote code execution vulnerability in Splunk Enterprise is being actively exploited by threat actors just days after technical details and proof-of-concept code were published, prompting the Cybersecurity and Infrastructure Security Agency (CISA) to mandate emergency patching for federal agencies.


The vulnerability, tracked as CVE-2026-20253, allows unauthenticated attackers to execute arbitrary code on vulnerable Splunk instances by exploiting a missing authentication control in the PostgreSQL sidecar service endpoint. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on June 18 and mandated remediation across federal systems by June 21—a compressed three-day window that underscores the severity of the threat.


## The Threat


CVE-2026-20253 represents a textbook case of authentication bypass escalating to remote code execution. The vulnerability stems from inadequate access controls on Splunk's PostgreSQL sidecar service endpoint, a component that handles database operations within Splunk Enterprise deployments.


The attack vector is straightforward:


  • An attacker with network access to a vulnerable Splunk instance requires no credentials
  • The unauthenticated attacker can invoke arbitrary file operations through the PostgreSQL sidecar endpoint
  • File creation and modification capabilities can be leveraged to achieve remote code execution

  • Cisco-owned Splunk disclosed the vulnerability in an official advisory, stating: "The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials."


    The severity is compounded by the fact that many Splunk deployments are exposed to the internet or accessible from untrusted networks. Organizations using Splunk for log aggregation, security monitoring, or compliance often place instances in network-accessible locations to facilitate centralized data collection—a deployment pattern that makes this vulnerability particularly dangerous.


    ## Background and Context


    Affected Versions:

  • Splunk Enterprise 10.2 before 10.2.4
  • Splunk Enterprise 10.0 before 10.0.7

  • Splunk released patches on June 10, 2026, providing users with the critical security updates needed to remediate the flaw. However, the rapid transition from disclosure to active exploitation reveals a troubling pattern: threat actors are increasingly moving to weaponize vulnerabilities within days of public disclosure.


    Timeline of Exploitation:


    | Date | Event |

    |------|-------|

    | June 10 | Splunk releases patches for CVE-2026-20253 |

    | June 12 | WatchTowr cybersecurity researchers publish PoC code and technical analysis |

    | June 18 | CISA confirms limited exploitation in the wild; adds CVE-2026-20253 to KEV catalog |

    | June 21 | Federal agency compliance deadline (3-day patch window) |


    The appearance of proof-of-concept code on June 12 represents a critical inflection point. Public PoC documentation significantly lowers the barrier to entry for threat actors, enabling even unsophisticated attackers to launch exploitation attempts. The confirmation of active exploitation just six days later demonstrates how quickly attackers mobilize when detailed technical information becomes available.


    ## Technical Details


    The PostgreSQL sidecar service in Splunk Enterprise serves as an auxiliary component for database operations. In vulnerable versions, this endpoint accepts requests without verifying the identity or authorization of the caller.


    Attack mechanics:


    1. File Operation Invocation: The attacker sends HTTP requests to the PostgreSQL sidecar endpoint, leveraging its file operation capabilities

    2. Arbitrary File Creation/Truncation: Without authentication validation, the endpoint processes requests to create new files or modify existing ones

    3. Remote Code Execution: By writing files to application directories or configuration paths, attackers can achieve command execution


    Common exploitation paths include:

  • Writing shell scripts to startup directories that execute with Splunk privileges
  • Modifying Python scripts or configuration files to inject malicious code
  • Creating scheduled task files that execute attacker-controlled commands

  • The fact that this is the first Splunk vulnerability to be added to CISA's KEV catalog is significant. Splunk has experienced security issues in the past, but none have triggered rapid active exploitation severe enough to warrant the emergency federal mandate status reserved for the most critical threats.


    ## Implications for Organizations


    Who is at risk?


    Splunk Enterprise deployments are ubiquitous across Fortune 500 companies, government agencies, financial institutions, and healthcare organizations. The software is a de facto standard for security information and event management (SIEM), log aggregation, and compliance monitoring. Any organization running vulnerable versions of Splunk Enterprise on versions 10.0 or 10.2 (prior to patched releases) faces immediate risk.


    Potential attack scenarios:


  • Compromise of security telemetry: Attackers gaining access to log aggregation systems could blind defenders to their presence
  • Lateral movement: Access to a Splunk instance provides foothold access that can be leveraged to move deeper into enterprise networks
  • Data exfiltration: Log data stored in Splunk often contains sensitive information, credentials in error messages, and intelligence about organizational systems
  • Supply chain positioning: Attackers could use compromised Splunk instances as staging points for broader supply chain attacks

  • The timing is particularly concerning. Organizations are typically in mid-year deployment cycles with stretched IT budgets and reduced staffing during summer months. Patch management teams may have lower availability, making the 72-hour federal compliance deadline extremely challenging for many agencies.


    ## Recommendations


    Immediate actions (within 24 hours):


  • Inventory vulnerable systems: Identify all Splunk Enterprise instances running versions 10.0.x or 10.2.x across your organization
  • Assess network exposure: Determine which instances are internet-accessible or reachable from untrusted networks
  • Prioritize patching: Tier systems by criticality—security monitoring instances should be patched first, followed by compliance and general log aggregation systems

  • Short-term measures (if patching cannot be completed immediately):


  • Network segmentation: Restrict access to PostgreSQL sidecar service endpoints to trusted internal networks only
  • WAF rules: Deploy web application firewall rules to block suspicious requests to vulnerable endpoints
  • Monitoring: Implement enhanced logging and alerting for attempts to access the PostgreSQL sidecar service

  • Patch deployment:


  • Update to Splunk Enterprise 10.2.4 or later for affected 10.2.x installations
  • Update to Splunk Enterprise 10.0.7 or later for affected 10.0.x installations
  • Test patches in non-production environments before broad deployment
  • Plan for service restarts during maintenance windows

  • ---


    ## HackWire Analysis


    This vulnerability exposes a critical gap in how security vendors approach sidecar and auxiliary service authentication. The PostgreSQL sidecar exists to handle database operations that core Splunk components need—but the logic that "internal services don't need authentication" is precisely the assumption that breaks when external attackers gain network access.


    What's particularly damning is that this is being actively exploited *before* most enterprise patch management teams have even identified their vulnerable instances. The three-day federal mandate reflects genuine alarm: federal systems running Splunk represent high-value targets, and CISA's aggressive timeline indicates they have evidence of scanning and exploitation attempts already in flight.


    The broader pattern is worth noting: critical infrastructure components like SIEM, logging, and monitoring tools are increasingly targeted because they represent informational chokepoints. A compromised Splunk instance doesn't just give attackers access to one system—it gives them visibility into your entire security posture, event logs, and detective controls. That asymmetry (attacker gains panoramic visibility, defenders lose it) is why these vulnerabilities move to KEV status so quickly.


    Organizations should use this as a forcing function to audit how their auxiliary services (sidecars, plugins, agent communications, API backends) handle authentication. If you're running Splunk, check your deployment now. If you're running other SIEM or log aggregation platforms, this pattern should trigger a security review of how those platforms authenticate internal component communication.


    The fact that this flaw reached active exploitation in six days—and warranted a federal emergency patch order—means your patch window has already effectively closed. Treat this as "must patch today," not "should patch this week."


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)