CVE Tools

Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)

watchTowr LabsBy Piotr Bazydlo (@chudyPB)17 min read

ResearchSplunk EnterpriseCVE-2026-20253

Our summary

Splunk Enterprise has been impacted by CVE-2026-20253, where the “PostgreSQL Sidecar Service Endpoint” does not properly enforce authentication controls and can be invoked in a way that leads to arbitrary file creation and truncation. The issue matters because it can be chained to achieve pre-auth RCE in certain deployments (notably Splunk Enterprise on AWS), despite the endpoint being intended to be reachable only locally. If you run affected versions of Splunk Enterprise, prioritize reviewing the vendor advisory and applying the recommended mitigations for CVE-2026-20253.

Read at watchTowr Labs

Below is the opening; the full story is at watchTowr Labs.

From watchTowr Labs

Three posts? In three days? Are we insane?

We're home alone, there's no one to stop us, and we're up past bedtime. So, we need to talk about Splunk.

On June 10th, Splunk published this CVE-2026-20253 advisory:

It has everything that we love:

  • No authentication requirements,
  • An almost full-mark CVSS score,
  • Claims to be a security product,
  • Vulnerability name longer than the average piece of spaghetti.…
Continue at watchTowr Labs

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store