Exploited Vulnerabilities Daily
🌐 English

Home › Splunk

CVE-2026-20253: Splunk Enterprise

EPSS96.9%No. 314 of 1739 in KEV
CVE year2026listed the same year
Same vendor in KEV1
Same product1
FieldValue
VendorSplunk
ProductEnterprise
NameSplunk Enterprise Missing Authentication for Critical Function Vulnerability
Added to KEV2026-06-18
US federal due date2026-06-21
Ransomware useUnknown
CWECWE-306

CISA description

Splunk Enterprise contains a missing authentication for critical function vulnerability which could allow an unauthenticated user to create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.

NVD — CVE-2026-20253

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Splunk Enterprise vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2026-06-18.