CVE-2026-20253
EUVD-2026-3608810.06.2026, 18:16
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| splunk | splunk | 10.2 ≤ 𝑥 < 10.2.4 | CNA |
| splunk | splunk | 10.0 ≤ 𝑥 < 10.0.7 | CNA |
| splunk | splunk | 10.4.2604 ≤ 𝑥 < 10.4.2604.3 | CNA |
| splunk | splunk | 10.2.2510 ≤ 𝑥 < 10.2.2510.14 | CNA |
Common Weakness Enumeration