Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication

A critical vulnerability chain in Splunk Enterprise has been disclosed, enabling unauthenticated attackers to achieve remote code execution (RCE) through a misconfigured PostgreSQL sidecar service. Tracked as CVE-2026-20253, the flaw has a CVSS score of 9.8 and affects Splunk Enterprise 10 and later. The issue originates from the PostgreSQL Sidecar Service, an internal component introduced […]

The post Splunk Enterprise Pre-Auth RCE Chain Exposes Database With Zero Authentication appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: