Splunk Enterprise Vulnerability
Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.
CVSS Score
9.8
CRITICAL
Published
18 Jun 2026 00:00
Modified
N/A
Vendor
Splunk
Product
Enterprise
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-306
Affected Systems
Splunk
Enterprise
Splunk
Enterprise
External Links
KEV Status
Known Exploited Vulnerability