๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerability
Summary
Splunk Enterprise has a critical security flaw where a PostgreSQL sidecar service endpoint (a supporting service that handles database connections) doesn't require authentication (proof of identity), allowing an attacker without credentials to create or delete arbitrary files. This vulnerability is currently being exploited in real attacks in the wild.
Vulnerability Details
EPSS: 1.7%
Yes
๐ฅ Actively Exploited
June 17, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-20253
First tracked: June 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 70%