CVE Research
sekurity-team
InSEKurity of the Week (CW25/2026): Splunk Enterprise Unauthenticated RCE via PostgreSQL Sidecar (CVE-2026-20253)
A missing-authentication flaw in Splunk Enterprise's PostgreSQL sidecar service lets unauthenticated attackers create and overwrite arbitrary files -- chained into remote code execution, actively exploited in the wild, and the first Splunk bug ever added to CISA KEV
Exploit
01