Vulnerabilities
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Cyber RTJune 13, 20263 min read

Splunk has issued updates for a critical vulnerability in Splunk Enterprise, CVE-2026-20253, rated 9.8 on CVSS. This flaw allows unauthenticated file operations and potential remote code execution via PostgreSQL sidecar service endpoints. The issue affects versions below 10.2.4 and 10.0.7, now fixed. Exploitation involves manipulating database dumps to execute malicious code. Users should promptly apply updates to mitigate risks.
Splunk has recently issued security updates to patch a critical vulnerability in Splunk Enterprise, which could potentially allow unauthenticated file operations and remote code execution. This vulnerability, identified as CVE-2026-20253, has been given a severity score of 9.8 on the CVSS scale, indicating its critical nature. The flaw affects Splunk Enterprise versions below 10.2.4 and 10.0.7, where an unauthenticated user could manipulate files through a PostgreSQL sidecar service endpoint due to a lack of authentication controls.
The vulnerability arises because the PostgreSQL sidecar service endpoint does not have proper authentication mechanisms, enabling any user with network access to perform file operations without needing credentials. To mitigate this issue, Splunk has released updates for affected versions: versions 10.0.0 to 10.0.6 have been fixed in 10.0.7, and versions 10.2.0 to 10.2.3 have been fixed in 10.2.4. Notably, Splunk Enterprise version 10.4 is not affected by this vulnerability, and Splunk Cloud is also safe as it does not utilize Postgres sidecars.
Further technical details about CVE-2026-20253 were disclosed by watchTowr Labs, highlighting the potential for pre-authenticated remote code execution through specific endpoints. The attack chain involves connecting to an attacker-controlled database and using the "/backup" endpoint to dump its contents into an arbitrary file. This dump can then be loaded into the local PostgreSQL instance using the "/restore" endpoint, with a "passfile" argument specifying the path to a ".pgpass" file containing the necessary credentials.
Attackers can exploit this vulnerability by defining a new function that uses the lo_export function to write attacker-controlled content to a file. This function is executed during the restoration process, allowing the attacker to authenticate and interact with the local database. Security researchers Piotr Bazydlo and Yordan Ganchev demonstrated how an attacker could quickly create a database dump template to achieve controlled file writes on the Splunk file system.
Once an attacker has the ability to write arbitrary files, they can escalate the attack to achieve remote code execution. This is done by overwriting a Python script that Splunk frequently executes, such as "/opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py," with a malicious payload. This sequence of actions enables the attacker to gain further control over the system.
The attack process involves creating a database with configurations that allow authentication without a password and granting permissions to invoke functions like lo_export. The attacker then uses the "/backup" endpoint to transfer a dump of the remote database to the Splunk file system and the "/restore" endpoint to load the malicious database dump. This triggers the execution of the malicious function and writes an attacker-controlled Python script to the system.
Although there is currently no evidence of this vulnerability being exploited in the wild, the detailed exploit information available could encourage threat actors to attempt opportunistic attacks. Therefore, it is crucial for users to promptly apply the provided fixes to protect their systems from potential exploitation. For those interested in staying informed about such security updates and exclusive content, following Splunk on platforms like Google News, Twitter, and LinkedIn is recommended.


