Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
ResearchSplunk EnterpriseCVE-2026-20253Our summary
Splunk Enterprise has been impacted by CVE-2026-20253, where the “PostgreSQL Sidecar Service Endpoint” does not properly enforce authentication controls and can be invoked in a way that leads to arbitrary file creation and truncation. The issue matters because it can be chained to achieve pre-auth RCE in certain deployments (notably Splunk Enterprise on AWS), despite the endpoint being intended to be reachable only locally. If you run affected versions of Splunk Enterprise, prioritize reviewing the vendor advisory and applying the recommended mitigations for CVE-2026-20253.
Below is the opening; the full story is at watchTowr Labs.
From watchTowr Labs
Three posts? In three days? Are we insane?
We're home alone, there's no one to stop us, and we're up past bedtime. So, we need to talk about Splunk.
On June 10th, Splunk published this CVE-2026-20253 advisory:
It has everything that we love:
- No authentication requirements,
- An almost full-mark CVSS score,
- Claims to be a security product,
- Vulnerability name longer than the average piece of spaghetti.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.