Threat reportVulnerabilityTL-2026-0786
CVE-2026-20253: Unauthenticated Pre-Auth RCE in Splunk Enterprise PostgreSQL Sidecar Service (SVD-2026-0603)
CVE-2026-20253 (TL-2026-0786), also tracked as SVD-2026-0603, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-13. It has no confirmed attribution, affects Splunk (Cisco) Splunk Enterprise, references 1 CVE (CVE-2026-20253), maps to 17 MITRE ATT&CK techniques (T1005, T1033, T1046), and is covered by 9 detection rules and 17 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 17MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-0786
- Threat ID
- TL-2026-0786
- Also known as
- SVD-2026-0603, Splunk PostgreSQL Sidecar Pre-Auth RCE
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- technology, financial, government, healthcare, managed-security-service-providers, enterprise
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 17
How CVE-2026-20253 works
CVE-2026-20253 (CVSS 9.8, CWE-306) is an unauthenticated remote code execution flaw in the Splunk Enterprise PostgreSQL sidecar service, whose /v1/postgres/recovery/backup and /restore endpoints lack authentication. watchTowr Labs chained connection-string injection, .pgpass credential reuse, and PostgreSQL lo_export() arbitrary file write to overwrite a Splunk Python script and gain code execution. Public PoC details were released; no confirmed in-the-wild exploitation at disclosure.
CVE-2026-20253 is a missing-authentication-for-critical-function (CWE-306) vulnerability in the PostgreSQL sidecar service shipped with Splunk Enterprise 10.x. The sidecar is a ~66MB Go binary (splunk-postgres) located under /opt/splunk/var/run/supervisor/pkg-run/ that backs newer Splunk data features. It exposes HTTP recovery endpoints — /v1/postgres/recovery/backup and /v1/postgres/recovery/restore — that listen on 127.0.0.1:5435 but are reachable externally because Splunk's main web application (port 8000) proxies raw requests through /en-US/splunkd/__raw/v1/postgres/recovery/. These endpoints perform no authentication of their own: the username supplied in the HTTP Authorization header is forwarded verbatim to pg_dump via the -U argument, delegating all auth to PostgreSQL itself, which an attacker can satisfy or bypass.
watchTowr Labs researchers Piotr Bazydlo (@chudyPB) and Yordan Ganchev published a full pre-auth RCE chain. (1) An attacker hits the backup endpoint with an empty Basic credential (Authorization: Basic Og==) and a controllable 'database' field. (2) Because libpq connection-string parameters override conflicting command-line options, injecting hostaddr=attacker.db into the 'database' field defeats the hardcoded -h localhost restriction, yielding SSRF that can dump data to or pull data from an attacker-controlled PostgreSQL server and pivot to internal resources. (3) The .pgpass file at /opt/splunk/var/packages/data/postgres/.pgpass leaks plaintext local DB credentials (e.g. user postgres_admin). (4) Using the restore endpoint with an injected passfile= parameter, the attacker authenticates to the local instance and runs arbitrary SQL. (5) A malicious PL/pgSQL function backed by lo_from_bytea()/lo_export() writes attacker-controlled bytes to any path on the Splunk filesystem during restore. (6) Overwriting a frequently executed script such as /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py converts the arbitrary file write into remote code execution in the Splunk context, and can also truncate or destroy arbitrary files (impacting integrity and availability).
The sidecar's exposure varies by deployment: it is disabled by default on on-premise installs (notably Windows) but enabled by default in Splunk Enterprise on AWS, making cloud-image deployments exploitable out of the box. Splunk Cloud Platform is not affected per the vendor advisory because it does not use these PostgreSQL sidecars. The vulnerability was disclosed in Splunk advisory SVD-2026-0603 on 2026-06-10, with watchTowr's technical write-up and detection tooling following on 2026-06-12, and broad press coverage on 2026-06-13. Because Splunk is a widely deployed SIEM that sits at the center of many SOCs, a pre-auth RCE on it is especially high-impact: a compromised Splunk host gives an adversary access to ingested logs, stored credentials, and a trusted pivot point. There were no confirmed in-the-wild exploits at publication, but the public PoC materially raises opportunistic exploitation risk. Note: a third-party Orca Security analysis claims a broader affected range (also 9.3.x/9.4.x and certain Cloud builds); this research follows the authoritative Splunk advisory SVD-2026-0603 for the affected/fixed matrix and records the discrepancy.
MITRE ATT&CK techniques used in TL-2026-0786
Collection
Discovery
T1033 System Owner/User Discovery; T1046 Network Service Discovery; T1083 File and Directory Discovery
Exfiltration
T1048 Exfiltration Over Alternative Protocol
Execution
T1059 Command and Scripting Interpreter; T1059.006 Python
Defense Evasion
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1485 Data Destruction; T1489 Service Stop
Persistence
T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary
Credential Access
T1552 Unsecured Credentials; T1552.001 Credentials In Files
stealth
Affected products and versions in CVE-2026-20253
- Splunk (Cisco) — Splunk Enterprise
Vulnerable versions: 10.0.0-10.0.6; 10.2.0-10.2.3
Fixed in: 10.0.7; 10.2.4 - Splunk (Cisco) — Splunk Enterprise 10.4
Fixed in: 10.4.0 (not affected) - Splunk (Cisco) — Splunk Cloud Platform
Fixed in: Not affected (PostgreSQL sidecars not used)
Remediation for CVE-2026-20253
Patches
- Splunk Enterprise 10.0.7 (fixes 10.0.0-10.0.6)
- Splunk Enterprise 10.2.4 (fixes 10.2.0-10.2.3)
- Splunk advisory SVD-2026-0603
Immediate actions
- Upgrade Splunk Enterprise to a fixed release: 10.0.7+ (for 10.0.x), 10.2.4+ (for 10.2.x); 10.4 is not affected.
- Inventory deployments — prioritize Splunk Enterprise on AWS, where the PostgreSQL sidecar is enabled by default and exploitable out of the box.
- Restrict network access to the Splunk web port (8000) and management interfaces to trusted administrators only.
Workarounds
- No vendor workaround is documented; mitigation is limited to patching plus network isolation of the Splunk web/management interfaces and disabling the PostgreSQL sidecar where not required.
Longer-term hardening
- Segment Splunk management/web interfaces from untrusted networks so the __raw proxy path cannot be reached by attackers.
- Deploy file integrity monitoring on /opt/splunk/etc/apps/**/bin/*.py and the postgres sidecar data directory to catch unauthorized overwrites.
- Add detection for access to /v1/postgres/recovery/* and /en-US/splunkd/__raw/v1/postgres/ proxy paths.
- Rotate any credentials stored in /opt/splunk/var/packages/data/postgres/.pgpass after patching if exposure is suspected.
CVEs associated with CVE-2026-20253
Weaknesses (CWE) in CVE-2026-20253
Timeline of CVE-2026-20253
- CVE-2026-20253 disclosed as part of Splunk's June 2026 advisory batch; vendors Splunk and Palo Alto Networks patch severe vulnerabilities concurrently (per SecurityWeek).
- Fixed releases made available: Splunk Enterprise 10.0.7 (for 10.0.0-10.0.6) and 10.2.4 (for 10.2.0-10.2.3); 10.4 and Splunk Cloud Platform unaffected.
- NVD publishes CVE-2026-20253 the same day as the vendor advisory, recording the missing-authentication (CWE-306) root cause and CVSS 9.8 base score.
- Splunk publishes advisory SVD-2026-0603 for CVE-2026-20253 (CVSS 9.8, CWE-306), titled 'Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint', crediting Alex Hordijk (hordalex).
- watchTowr Labs releases a vulnerability-check / detection tool to identify exposed and exploitable Splunk PostgreSQL sidecar endpoints.
- watchTowr Labs researchers Piotr Bazydlo (@chudyPB) and Yordan Ganchev publish the full pre-auth RCE chain technical write-up detailing connection-string injection, .pgpass credential reuse, and lo_export() arbitrary file write.
- No confirmed in-the-wild exploitation observed at publication; public PoC availability and default-on exposure on Splunk Enterprise for AWS increase opportunistic exploitation likelihood.
- Threadlinqs Intelligence ingests and tracks CVE-2026-20253 as a critical pre-auth RCE on a widely deployed SIEM with public PoC details.
- Orca Security publishes an independent analysis; it claims a broader affected range (also 9.3.x/9.4.x and certain Cloud builds), a discrepancy recorded against the authoritative SVD-2026-0603 matrix.
- The Hacker News, Cyber Security News, GBHackers, SecurityWeek and SecurityOnline report the flaw, emphasizing the CVSS 9.8 pre-auth RCE on a widely deployed SIEM.
Sources cited for CVE-2026-20253
- Splunk Advisory SVD-2026-0603: Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint
- watchTowr Labs: Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)
- NVD - CVE-2026-20253
- Orca Security: CVE-2026-20253 Splunk Enterprise RCE & Unauthenticated File Operations
- The Hacker News: Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
- Cyber Security News: Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication
- GBHackers: Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases
- SecurityWeek: Splunk, Palo Alto Networks Patch Severe Vulnerabilities
- SecurityOnline: Splunk Enterprise Vulnerabilities — CVSS 9.8 Flaw Uncovered
- Intruder CVEMon: CVE-2026-20253 Overview, Insights & Trends
- cvefeed.io: CVE-2026-20253 Detail
Detection coverage for TL-2026-0786
As of 2026-06-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0786 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.