Threat reportVulnerabilityTL-2026-0786

CVE-2026-20253: Unauthenticated Pre-Auth RCE in Splunk Enterprise PostgreSQL Sidecar Service (SVD-2026-0603)

criticalACTIVE

CVE-2026-20253 (TL-2026-0786), also tracked as SVD-2026-0603, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-06-13. It has no confirmed attribution, affects Splunk (Cisco) Splunk Enterprise, references 1 CVE (CVE-2026-20253), maps to 17 MITRE ATT&CK techniques (T1005, T1033, T1046), and is covered by 9 detection rules and 17 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
17MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
17Indicators of compromise

Key facts for TL-2026-0786

Threat ID
TL-2026-0786
Also known as
SVD-2026-0603, Splunk PostgreSQL Sidecar Pre-Auth RCE
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
technology, financial, government, healthcare, managed-security-service-providers, enterprise
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
17

How CVE-2026-20253 works

CVE-2026-20253 (CVSS 9.8, CWE-306) is an unauthenticated remote code execution flaw in the Splunk Enterprise PostgreSQL sidecar service, whose /v1/postgres/recovery/backup and /restore endpoints lack authentication. watchTowr Labs chained connection-string injection, .pgpass credential reuse, and PostgreSQL lo_export() arbitrary file write to overwrite a Splunk Python script and gain code execution. Public PoC details were released; no confirmed in-the-wild exploitation at disclosure.

CVE-2026-20253 is a missing-authentication-for-critical-function (CWE-306) vulnerability in the PostgreSQL sidecar service shipped with Splunk Enterprise 10.x. The sidecar is a ~66MB Go binary (splunk-postgres) located under /opt/splunk/var/run/supervisor/pkg-run/ that backs newer Splunk data features. It exposes HTTP recovery endpoints — /v1/postgres/recovery/backup and /v1/postgres/recovery/restore — that listen on 127.0.0.1:5435 but are reachable externally because Splunk's main web application (port 8000) proxies raw requests through /en-US/splunkd/__raw/v1/postgres/recovery/. These endpoints perform no authentication of their own: the username supplied in the HTTP Authorization header is forwarded verbatim to pg_dump via the -U argument, delegating all auth to PostgreSQL itself, which an attacker can satisfy or bypass.

watchTowr Labs researchers Piotr Bazydlo (@chudyPB) and Yordan Ganchev published a full pre-auth RCE chain. (1) An attacker hits the backup endpoint with an empty Basic credential (Authorization: Basic Og==) and a controllable 'database' field. (2) Because libpq connection-string parameters override conflicting command-line options, injecting hostaddr=attacker.db into the 'database' field defeats the hardcoded -h localhost restriction, yielding SSRF that can dump data to or pull data from an attacker-controlled PostgreSQL server and pivot to internal resources. (3) The .pgpass file at /opt/splunk/var/packages/data/postgres/.pgpass leaks plaintext local DB credentials (e.g. user postgres_admin). (4) Using the restore endpoint with an injected passfile= parameter, the attacker authenticates to the local instance and runs arbitrary SQL. (5) A malicious PL/pgSQL function backed by lo_from_bytea()/lo_export() writes attacker-controlled bytes to any path on the Splunk filesystem during restore. (6) Overwriting a frequently executed script such as /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py converts the arbitrary file write into remote code execution in the Splunk context, and can also truncate or destroy arbitrary files (impacting integrity and availability).

The sidecar's exposure varies by deployment: it is disabled by default on on-premise installs (notably Windows) but enabled by default in Splunk Enterprise on AWS, making cloud-image deployments exploitable out of the box. Splunk Cloud Platform is not affected per the vendor advisory because it does not use these PostgreSQL sidecars. The vulnerability was disclosed in Splunk advisory SVD-2026-0603 on 2026-06-10, with watchTowr's technical write-up and detection tooling following on 2026-06-12, and broad press coverage on 2026-06-13. Because Splunk is a widely deployed SIEM that sits at the center of many SOCs, a pre-auth RCE on it is especially high-impact: a compromised Splunk host gives an adversary access to ingested logs, stored credentials, and a trusted pivot point. There were no confirmed in-the-wild exploits at publication, but the public PoC materially raises opportunistic exploitation risk. Note: a third-party Orca Security analysis claims a broader affected range (also 9.3.x/9.4.x and certain Cloud builds); this research follows the authoritative Splunk advisory SVD-2026-0603 for the affected/fixed matrix and records the discrepancy.

MITRE ATT&CK techniques used in TL-2026-0786

Collection

T1005 Data from Local System

Discovery

T1033 System Owner/User Discovery; T1046 Network Service Discovery; T1083 File and Directory Discovery

Exfiltration

T1048 Exfiltration Over Alternative Protocol

Execution

T1059 Command and Scripting Interpreter; T1059.006 Python

Defense Evasion

T1070.004 File Deletion

Initial Access

T1190 Exploit Public-Facing Application

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1485 Data Destruction; T1489 Service Stop

Persistence

T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary

Credential Access

T1552 Unsecured Credentials; T1552.001 Credentials In Files

stealth

T1574 Hijack Execution Flow

Affected products and versions in CVE-2026-20253

  • Splunk (Cisco) — Splunk Enterprise
    Vulnerable versions: 10.0.0-10.0.6; 10.2.0-10.2.3
    Fixed in: 10.0.7; 10.2.4
  • Splunk (Cisco) — Splunk Enterprise 10.4
    Fixed in: 10.4.0 (not affected)
  • Splunk (Cisco) — Splunk Cloud Platform
    Fixed in: Not affected (PostgreSQL sidecars not used)

Remediation for CVE-2026-20253

Patches

  • Splunk Enterprise 10.0.7 (fixes 10.0.0-10.0.6)
  • Splunk Enterprise 10.2.4 (fixes 10.2.0-10.2.3)
  • Splunk advisory SVD-2026-0603

Immediate actions

  • Upgrade Splunk Enterprise to a fixed release: 10.0.7+ (for 10.0.x), 10.2.4+ (for 10.2.x); 10.4 is not affected.
  • Inventory deployments — prioritize Splunk Enterprise on AWS, where the PostgreSQL sidecar is enabled by default and exploitable out of the box.
  • Restrict network access to the Splunk web port (8000) and management interfaces to trusted administrators only.

Workarounds

  • No vendor workaround is documented; mitigation is limited to patching plus network isolation of the Splunk web/management interfaces and disabling the PostgreSQL sidecar where not required.

Longer-term hardening

  • Segment Splunk management/web interfaces from untrusted networks so the __raw proxy path cannot be reached by attackers.
  • Deploy file integrity monitoring on /opt/splunk/etc/apps/**/bin/*.py and the postgres sidecar data directory to catch unauthorized overwrites.
  • Add detection for access to /v1/postgres/recovery/* and /en-US/splunkd/__raw/v1/postgres/ proxy paths.
  • Rotate any credentials stored in /opt/splunk/var/packages/data/postgres/.pgpass after patching if exposure is suspected.

CVEs associated with CVE-2026-20253

CVE-2026-20253

Weaknesses (CWE) in CVE-2026-20253

CWE-306

Timeline of CVE-2026-20253

  • CVE-2026-20253 disclosed as part of Splunk's June 2026 advisory batch; vendors Splunk and Palo Alto Networks patch severe vulnerabilities concurrently (per SecurityWeek).
  • Fixed releases made available: Splunk Enterprise 10.0.7 (for 10.0.0-10.0.6) and 10.2.4 (for 10.2.0-10.2.3); 10.4 and Splunk Cloud Platform unaffected.
  • NVD publishes CVE-2026-20253 the same day as the vendor advisory, recording the missing-authentication (CWE-306) root cause and CVSS 9.8 base score.
  • Splunk publishes advisory SVD-2026-0603 for CVE-2026-20253 (CVSS 9.8, CWE-306), titled 'Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint', crediting Alex Hordijk (hordalex).
  • watchTowr Labs releases a vulnerability-check / detection tool to identify exposed and exploitable Splunk PostgreSQL sidecar endpoints.
  • watchTowr Labs researchers Piotr Bazydlo (@chudyPB) and Yordan Ganchev publish the full pre-auth RCE chain technical write-up detailing connection-string injection, .pgpass credential reuse, and lo_export() arbitrary file write.
  • No confirmed in-the-wild exploitation observed at publication; public PoC availability and default-on exposure on Splunk Enterprise for AWS increase opportunistic exploitation likelihood.
  • Threadlinqs Intelligence ingests and tracks CVE-2026-20253 as a critical pre-auth RCE on a widely deployed SIEM with public PoC details.
  • Orca Security publishes an independent analysis; it claims a broader affected range (also 9.3.x/9.4.x and certain Cloud builds), a discrepancy recorded against the authoritative SVD-2026-0603 matrix.
  • The Hacker News, Cyber Security News, GBHackers, SecurityWeek and SecurityOnline report the flaw, emphasizing the CVSS 9.8 pre-auth RCE on a widely deployed SIEM.

Sources cited for CVE-2026-20253

Detection coverage for TL-2026-0786

As of 2026-06-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0786 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
17 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats