Executive brief
Splunk Enterprise and Splunk Cloud Platform, which are used for searching, monitoring, and analyzing machine-generated data, contain a security flaw in a background database service. An unauthorized person can remotely create or delete files on the server without needing a password. This could lead to a total system takeover, data loss, or significant operational disruption.
Technical details
A missing authentication for critical function vulnerability (CWE-306) exists in the PostgreSQL sidecar service endpoint of Splunk Enterprise and Splunk Cloud Platform. The endpoint fails to enforce authentication controls, allowing any network-reachable attacker to invoke file operations without credentials. Specifically, an attacker can create or truncate arbitrary files on the underlying filesystem. This capability can be leveraged to achieve remote code execution (RCE). The vulnerability affects Splunk Enterprise versions 10.0.x (before 10.0.7) and 10.2.x (before 10.2.4), as well as specific Splunk Cloud Platform versions. Users are advised to upgrade to fixed versions or mitigate the risk by disabling the PostgreSQL sidecar service.
Affected products
- Splunk Splunk Enterprise 10.2.x before 10.2.4, 10.0.x before 10.0.7
- Splunk Splunk Cloud Platform before 10.4.2604.3, before 10.2.2510.14
Timeline
- 2026-06-10: disclosed: Initial CVE entry received from Cisco/Splunk
- 2026-06-15: advisory: Vendor advisory published by Splunk
- 2026-06-18: other: NVD publication date