/Vulnerability Library

Splunk Enterprise & Cloud Platform - Unrestricted File Upload

CVE-2026-20253
Verified

Description

In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

Severity

Critical

Published Date

June 12, 2026

Template Author

watchtowrlabs, dhiyaneshdk

CVE-2026-20253.yaml
id: CVE-2026-20253

info:
  name: Splunk Enterprise & Cloud Platform - Unrestricted File Upload
  author: watchtowrlabs,DhiyaneshDk
  severity: critical
  description: |
    In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.
  impact: |
    Unauthenticated attackers can create or truncate arbitrary files, potentially leading to data loss or system compromise.
  remediation: |
    Upgrade to Splunk Enterprise 10.2.4, 10.0.7 and Splunk Cloud Platform 10.4.2604.3, 10.2.2510.14 or later.
  reference:
    - https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
    - https://github.com/watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253/blob/main/watchTowr-vs-Splunk-CVE-2026-20253.py
  metadata:
    verified: true
    max-request: 1
    fofa-query: body="enterprise" && body="splunk"
  tags: cve,cve2026,splunk,postgres,backup,vkev,kev

http:
  - raw:
      - |
        POST /{{region}}/splunkd/__raw/v1/postgres/recovery/backup HTTP/1.1
        Host: {{Hostname}}
        Authorization: Basic ZGFnOg==

    payloads:
      region:
        - "en-US"

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "Failed to decode"

      - type: status
        status:
          - 400
# digest: 490a0046304402201da430780814d7865c4b2fcab64e649e06b260eac684ea5f5860ea46bc4dd3030220433b9e7f6979eecf0350f43d916747e20ab31f1620f4875672d5f25a8c6831a1:922c64590222798bb761d5b6d8e72950
9.5Severity

CVSS Metrics

References

https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/https://github.com/watchtowrlabs/watchTowr-vs-Splunk-CVE-2026-20253/blob/main/watchTowr-vs-Splunk-CVE-2026-20253.py

Remediation Steps

Upgrade to Splunk Enterprise 10.2.4, 10.0.7 and Splunk Cloud Platform 10.4.2604.3, 10.2.2510.14 or later.