Missing Authentication for Critical Function in Splunk Enterprise - CVE-2026-20253
Published: June 12, 2026
Splunk Enterprise
Detailed vulnerability description
The vulnerability allows a remote attacker to create or truncate arbitrary files.
The vulnerability exists due to improper authentication in the PostgreSQL sidecar service endpoint when handling file operation requests. A remote attacker can send crafted requests to create or truncate arbitrary files.
The endpoint can be reached without credentials.