Four vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and the Splunk Secure Gateway app have been disclosed, led by CVE-2026-20253 (CVSS 9.8), a critical unauthenticated arbitrary file creation/truncation flaw in a PostgreSQL sidecar service endpoint. A second critical flaw, CVE-2026-20251 (CVSS 8.8), enables remote code execution via unsafe deserialization using the jsonpickle Python library with only low-privilege access. Two additional high-severity issues cover stored XSS in dashboard HTML panels and SSRF in the PDF export feature. No public exploits or active exploitation have been reported, but the unauthenticated nature of the primary flaw makes patching urgent. Affected versions span Splunk Enterprise 9.3–10.2 and multiple Splunk Cloud Platform tracks. Immediate upgrade to patched versions is the primary recommendation; no workaround exists for CVE-2026-20253.

4m read timeFrom orca.security
Post cover image
Table of contents
Executive SummaryAbout the Vulnerability: CVE-2026-20253 and Related CVEsRisk ImpactMitigation RecommendationsHow can Orca help?
154 Impressions