# CVE-2026-20253: Unauthenticated Pre-Auth RCE in Splunk Enterprise PostgreSQL Sidecar Service (SVD-2026-0603)

> CVE-2026-20253 (CVSS 9.8, CWE-306) is an unauthenticated remote code execution flaw in the Splunk Enterprise PostgreSQL sidecar service, whose /v1/postgres/recovery/backup and /restore endpoints lack authentication. watchTowr Labs chained connection-string injection, .pgpass credential reuse, and PostgreSQL lo_export() arbitrary file write to overwrite a Splunk Python script and gain code execution. Public PoC details were released; no confirmed in-the-wild exploitation at disclosure.

- **Published:** 2026-06-13T00:00:00Z
- **Last reviewed:** 2026-06-13T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0786
- **ID:** TL-2026-0786
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-20253

## Description

CVE-2026-20253 is a missing-authentication-for-critical-function (CWE-306) vulnerability in the PostgreSQL sidecar service shipped with Splunk Enterprise 10.x. The sidecar is a ~66MB Go binary (splunk-postgres) located under /opt/splunk/var/run/supervisor/pkg-run/ that backs newer Splunk data features. It exposes HTTP recovery endpoints — /v1/postgres/recovery/backup and /v1/postgres/recovery/restore — that listen on 127.0.0.1:5435 but are reachable externally because Splunk's main web application (port 8000) proxies raw requests through /en-US/splunkd/__raw/v1/postgres/recovery/. These endpoints perform no authentication of their own: the username supplied in the HTTP Authorization header is forwarded verbatim to pg_dump via the -U argument, delegating all auth to PostgreSQL itself, which an attacker can satisfy or bypass.

watchTowr Labs researchers Piotr Bazydlo (@chudyPB) and Yordan Ganchev published a full pre-auth RCE chain. (1) An attacker hits the backup endpoint with an empty Basic credential (Authorization: Basic Og==) and a controllable 'database' field. (2) Because libpq connection-string parameters override conflicting command-line options, injecting hostaddr=attacker.db into the 'database' field defeats the hardcoded -h localhost restriction, yielding SSRF that can dump data to or pull data from an attacker-controlled PostgreSQL server and pivot to internal resources. (3) The .pgpass file at /opt/splunk/var/packages/data/postgres/.pgpass leaks plaintext local DB credentials (e.g. user postgres_admin). (4) Using the restore endpoint with an injected passfile= parameter, the attacker authenticates to the local instance and runs arbitrary SQL. (5) A malicious PL/pgSQL function backed by lo_from_bytea()/lo_export() writes attacker-controlled bytes to any path on the Splunk filesystem during restore. (6) Overwriting a frequently executed script such as /opt/splunk/etc/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py converts the arbitrary file write into remote code execution in the Splunk context, and can also truncate or destroy arbitrary files (impacting integrity and availability).

The sidecar's exposure varies by deployment: it is disabled by default on on-premise installs (notably Windows) but enabled by default in Splunk Enterprise on AWS, making cloud-image deployments exploitable out of the box. Splunk Cloud Platform is not affected per the vendor advisory because it does not use these PostgreSQL sidecars. The vulnerability was disclosed in Splunk advisory SVD-2026-0603 on 2026-06-10, with watchTowr's technical write-up and detection tooling following on 2026-06-12, and broad press coverage on 2026-06-13. Because Splunk is a widely deployed SIEM that sits at the center of many SOCs, a pre-auth RCE on it is especially high-impact: a compromised Splunk host gives an adversary access to ingested logs, stored credentials, and a trusted pivot point. There were no confirmed in-the-wild exploits at publication, but the public PoC materially raises opportunistic exploitation risk. Note: a third-party Orca Security analysis claims a broader affected range (also 9.3.x/9.4.x and certain Cloud builds); this research follows the authoritative Splunk advisory SVD-2026-0603 for the affected/fixed matrix and records the discrepancy.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059.006 Python
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1574 Hijack Execution Flow
- T1554 Compromise Host Software Binary
- T1552.001 Credentials In Files
- T1552 Unsecured Credentials
- T1083 File and Directory Discovery
- T1046 Network Service Discovery
- T1033 System Owner/User Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1048 Exfiltration Over Alternative Protocol
- T1070.004 File Deletion
- T1485 Data Destruction
- T1489 Service Stop

## Sources

- [Splunk Advisory SVD-2026-0603: Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint](https://advisory.splunk.com/advisories/SVD-2026-0603)
- [watchTowr Labs: Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE)](https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/)
- [NVD - CVE-2026-20253](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20253)
- [Orca Security: CVE-2026-20253 Splunk Enterprise RCE & Unauthenticated File Operations](https://orca.security/resources/blog/cve-2026-20253-splunk-enterprise-rce-unauthenticated-file-operations/)
- [The Hacker News: Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication](https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html)
- [Cyber Security News: Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication](https://cybersecuritynews.com/splunk-enterprise-pre-auth-rce-chain-exposes/)
- [GBHackers: Critical Splunk Enterprise Pre-Auth RCE Chain Exposes Databases](https://gbhackers.com/critical-splunk-enterprise-pre-auth/)
- [SecurityWeek: Splunk, Palo Alto Networks Patch Severe Vulnerabilities](https://www.securityweek.com/splunk-palo-alto-networks-patch-severe-vulnerabilities/)
- [SecurityOnline: Splunk Enterprise Vulnerabilities — CVSS 9.8 Flaw Uncovered](https://securityonline.info/splunk-enterprise-vulnerabilities-cvss-9-8/)
- [Intruder CVEMon: CVE-2026-20253 Overview, Insights & Trends](https://cvemon.intruder.io/cves/CVE-2026-20253)
- [cvefeed.io: CVE-2026-20253 Detail](https://cvefeed.io/vuln/detail/CVE-2026-20253)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0786
