9.7 C
Canberra
Sunday, June 14, 2026

Vital Splunk Enterprise Flaw Lets Attackers Run Code With out Authentication


Ravie LakshmananJun 13, 2026Vulnerability / Enterprise Software program

Vital Splunk Enterprise Flaw Lets Attackers Run Code With out Authentication

Splunk has launched safety updates to handle a important safety flaw in Splunk Enterprise that could possibly be exploited to conduct unauthenticated file operations and even distant code execution.

The vulnerability, tracked as CVE-2026-20253, is rated 9.8 on the CVSS scoring system.

“In Splunk Enterprise variations under 10.2.4 and 10.0.7, an unauthenticated consumer may create or truncate arbitrary information by way of a PostgreSQL sidecar service endpoint,” Splunk stated in an alert this week.

“The vulnerability exists as a result of the PostgreSQL sidecar service endpoint lacks authentication controls, permitting any network-reachable consumer to invoke file operations with out credentials.”

The problem has been addressed within the following variations –

  • Splunk Enterprise 10.0.0 to 10.0.6 – Fastened in 10.0.7
  • Splunk Enterprise 10.2.0 to 10.2.3 – Fastened in 10.2.4
  • Splunk Enterprise 10.4 – Not affected

Splunk, which is a part of Cisco, stated Splunk Cloud isn’t impacted by the vulnerability as Postgres sidecars aren’t used within the product.

What the Flaw is All About

On Friday, watchTowr Labs launched further technical particulars of CVE-2026-20253, stating it could possibly be exploited to realize pre-authenticated distant code execution on vulnerable programs by way of the “/v1/postgres/restoration/backup” and “/v1/postgres/restoration/restore” endpoints.

The assault chain works as follows –

  • Hook up with an attacker-controlled database and dump its contents into an arbitrary file utilizing the /backup endpoint
  • Load the dump of the attacker-controlled database into the native PostgreSQL occasion utilizing the /restore endpoint by together with a “passfile” argument that specifies the trail to a “.pgpass” file (“/decide/splunk/var/packages/information/postgres/.pgpass”) containing the password for the “postgres_admin” consumer
  • SQL queries outlined within the database dump will get executed by Splunk’s PostgreSQL occasion

An attacker may weaponize this weak spot to outline a brand new perform that makes use of lo_export – a perform used to extract a BLOB from the database and reserve it as a file on the file system – to put in writing attacker-controlled content material to a file, following which the perform will get executed through the restoration course of.

“At this level, we are able to authenticate, restore attacker-controlled SQL, and work together with the native database,” safety researchers Piotr Bazydlo and Yordan Ganchev stated. “As soon as we may restore attacker-controlled SQL into the native PostgreSQL occasion, we rapidly put collectively a database dump template that gave us a managed file write.”

Armed with an arbitrary file write primitive on the Splunk file system, an attacker may escalate additional to distant code execution by overwriting a Python script that Splunk often executes (e.g., “/decide/splunk/and so forth/apps/splunk_secure_gateway/bin/ssg_enable_modular_input.py”) to incorporate the malicious payload.

Your complete sequence of actions is under –

  • Create a database and configure it such {that a} consumer can authenticate with out a password and grant it ample permissions to invoke capabilities like lo_export
  • Use the /backup endpoint to drop a dump of the distant database onto the Splunk file system
  • Use the /restore endpoint to load the malicious database dump, set off execution of the malicious perform through the restore course of, and write an attacker-controlled Python script to the Splunk file system

Though there isn’t any proof of the flaw being exploited within the wild, the supply of the exploit specifics will be sufficient to drive risk actors to set off opportunistic makes an attempt. It is important that customers transfer rapidly to use the fixes to remain protected.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

[td_block_social_counter facebook="tagdiv" twitter="tagdivofficial" youtube="tagdiv" style="style8 td-social-boxed td-social-font-icons" tdc_css="eyJhbGwiOnsibWFyZ2luLWJvdHRvbSI6IjM4IiwiZGlzcGxheSI6IiJ9LCJwb3J0cmFpdCI6eyJtYXJnaW4tYm90dG9tIjoiMzAiLCJkaXNwbGF5IjoiIn0sInBvcnRyYWl0X21heF93aWR0aCI6MTAxOCwicG9ydHJhaXRfbWluX3dpZHRoIjo3Njh9" custom_title="Stay Connected" block_template_id="td_block_template_8" f_header_font_family="712" f_header_font_transform="uppercase" f_header_font_weight="500" f_header_font_size="17" border_color="#dd3333"]
- Advertisement -spot_img

Latest Articles