ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-20253

CRITICAL Export PDF

Splunk Enterprise Vulnerability

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

CVSS Score
9.8
CRITICAL
Published
18 Jun 2026 00:00
Modified
N/A
Vendor
Splunk
Product
Enterprise
Source
CIRCL

Affected Versions

Fix Vendor Patch / Mitigation Available

Weaknesses (CWE)

CWE-306

Affected Systems

Splunk
Enterprise
Splunk
Enterprise

KEV Status

Known Exploited Vulnerability