Splunk Enterprise Unauthenticated Arbitrary File Operations/RCE (CVE-2026-20253): Overview and Takeaways
netspi.com | vulnerability | CVE-2026-20253 | #rce | #postgresql | #poc | #splunk | #patch-now | #auth-bypass | #cve-2026-20253
Summary
CVE-2026-20253 (CVSS 9.8) exposes an unauthenticated PostgreSQL sidecar endpoint in Splunk Enterprise 10.0.x/10.2.x, allowing file writes that chain to RCE via lo_export; a public PoC exists.
- CVE
- CVE-2026-20253
- Published
- Collected
Skip to content