---
title: "Critical Splunk Enterprise Vulnerabilities Allow Unauthenticated File Operations and Remote Code Execution"
url: https://daily.dev/posts/critical-splunk-enterprise-vulnerabilities-allow-unauthenticated-file-operations-and-remote-code-exe-bgqci6rdk
source_url: https://orca.security/resources/blog/cve-2026-20253-splunk-enterprise-rce-unauthenticated-file-operations
type: article
source: "Orca Security Blog"
published: 2026-06-11T17:05:08.557Z
updated: 2026-06-11T17:05:34.919Z
tags: ["security", "logging"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Critical Splunk Enterprise Vulnerabilities Allow Unauthenticated File Operations and Remote Code Execution

**[Orca Security Blog](https://daily.dev/sources/orca-security-blog)** · 4 min read · 0 upvotes · 0 comments

## Summary

Four vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and the Splunk Secure Gateway app have been disclosed, led by CVE-2026-20253 (CVSS 9.8), a critical unauthenticated arbitrary file creation/truncation flaw in a PostgreSQL sidecar service endpoint. A second critical flaw, CVE-2026-20251 (CVSS 8.8), enables remote code execution via unsafe deserialization using the jsonpickle Python library with only low-privilege access. Two additional high-severity issues cover stored XSS in dashboard HTML panels and SSRF in the PDF export feature. No public exploits or active exploitation have been reported, but the unauthenticated nature of the primary flaw makes patching urgent. Affected versions span Splunk Enterprise 9.3–10.2 and multiple Splunk Cloud Platform tracks. Immediate upgrade to patched versions is the primary recommendation; no workaround exists for CVE-2026-20253.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://orca.security/resources/blog/cve-2026-20253-splunk-enterprise-rce-unauthenticated-file-operations>

## Similar posts on daily.dev

- [CISA: Splunk Enterprise flaw actively exploited, patch by Sunday](https://daily.dev/posts/cisa-splunk-enterprise-flaw-actively-exploited-patch-by-sunday-z0vm1ip1q) · BleepingComputer · 0 upvotes · 0 comments
- [How CVE-2026-20253 Turns Splunk’s PostgreSQL Sidecar Into an Open Door](https://daily.dev/posts/how-cve-2026-20253-turns-splunk-s-postgresql-sidecar-into-an-open-door-eoqau7eyh) · Latest Hacking News · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#logging](https://daily.dev/tags/logging)

[View this post on daily.dev](https://daily.dev/posts/critical-splunk-enterprise-vulnerabilities-allow-unauthenticated-file-operations-and-remote-code-exe-bgqci6rdk)
