CVE-2026-20253CISA KEV: Actively Exploited

Splunk Enterprise Missing Authentication for Critical Function Vulnerability

Published Jun 18, 2026·Updated Jun 18, 2026

Description

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

Public Exploits & PoCs3 found

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free