{"id":275963,"date":"2026-06-19T06:52:00","date_gmt":"2026-06-19T10:52:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/06\/19\/u-s-cisa-adds-splunk-enterprise-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-agencies-to-fix-it-by-sunday\/"},"modified":"2026-06-19T08:55:14","modified_gmt":"2026-06-19T12:55:14","slug":"u-s-cisa-adds-splunk-enterprise-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-agencies-to-fix-it-by-sunday","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/06\/19\/u-s-cisa-adds-splunk-enterprise-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-agencies-to-fix-it-by-sunday\/","title":{"rendered":"U.S. CISA adds Splunk Enterprise\u00a0flaw to its Known Exploited Vulnerabilities catalog and urges agencies to fix it by Sunday"},"content":{"rendered":"<p><a href=\"https:\/\/securityaffairs.com\/193888\/security\/u-s-cisa-adds-splunk-enterprise-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-agencies-to-fix-it-by-sunday.html\">U.S. CISA adds Splunk Enterprise\u00a0flaw to its Known Exploited Vulnerabilities catalog and urges agencies to fix it by Sunday<\/a><\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/193888\/security\/u-s-cisa-adds-splunk-enterprise-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-agencies-to-fix-it-by-sunday.html\">https:\/\/securityaffairs.com\/193888\/security\/u-s-cisa-adds-splunk-enterprise-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-agencies-to-fix-it-by-sunday.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-06-19 06:52:00<\/a><\/p>\n<p>Source Domain: <a href=\"securityaffairs.com\">securityaffairs.com<\/a><\/p>\n<p><h2>U.S. CISA adds Splunk Enterprise\u00a0flaw to its Known Exploited Vulnerabilities catalog and urges agencies to fix it by Sunday<\/h2>\n<\/p>\n<p>\t\t\t\t\t\t\t<span> Pierluigi Paganini<\/span><br \/>\n\t\t\t\t\t\t\t<span><img decoding=\"async\" src=\"https:\/\/securityaffairs.com\/wp-content\/themes\/security_affairs\/images\/clock-icon.svg\" alt=\"\"\/> June 19, 2026<\/span><\/p>\n<p>\t\t\t\t\t\t<img decoding=\"async\" class=\"img-fluid mb-4\" src=\"https:\/\/i0.wp.com\/securityaffairs.com\/wp-content\/uploads\/2020\/07\/CISA.jpeg?fit=700%2C368&#038;ssl=1\" alt=\"\"\/><\/p>\n<h2 class=\"wp-block-heading\">U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Splunk Enterprise\u00a0flaw to its Known Exploited Vulnerabilities catalog.<\/h2>\n<p class=\"wp-block-paragraph\">The U.S. Cybersecurity and Infrastructure Security Agency (CISA)\u00a0added a Splunk Enterprise\u00a0flaw, tracked as CVE-2026-20253 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog.<\/p>\n<p class=\"wp-block-paragraph\">The flaw CVE-2026-20253 is an improper authentication vulnerability in the PostgreSQL sidecar service of Splunk Enterprise that allows unauthenticated remote attackers to create or truncate arbitrary files on affected systems. The issue stems from missing authentication controls on a PostgreSQL sidecar service endpoint, enabling any network-reachable user to invoke file operations without valid credentials. <\/p>\n<p class=\"wp-block-paragraph\">\u201cIn Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.\u201d reads the advisory. \u201cThe vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Successful exploitation could lead to data loss, service disruption, or further compromise depending on the files targeted. <\/p>\n<p class=\"wp-block-paragraph\">The vulnerability affects Splunk Enterprise 10.2 versions prior to 10.2.4 and 10.0 versions prior to 10.0.7, while versions 9.4 and earlier are not impacted. Organizations unable to immediately apply the available patches should mitigate the risk by disabling the PostgreSQL sidecar service.<\/p>\n<p class=\"wp-block-paragraph\">Splunk PSIRT confirmed it is aware of limited active exploitation of the vulnerability and urged customers to immediately upgrade to patched versions to mitigate the risk. The&#8230;<\/p>\n<p><a href=\"https:\/\/securityaffairs.com\/193888\/security\/u-s-cisa-adds-splunk-enterprise-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-agencies-to-fix-it-by-sunday.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>U.S. CISA adds Splunk Enterprise\u00a0flaw to its Known Exploited Vulnerabilities catalog and urges agencies to&#8230;<\/p>\n","protected":false},"author":1,"featured_media":275964,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/securityaffairs.com\/wp-content\/uploads\/2020\/07\/CISA.jpeg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,27],"class_list":["post-275963","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-vulnerability"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/275963"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=275963"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/275963\/revisions"}],"predecessor-version":[{"id":275966,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/275963\/revisions\/275966"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/275964"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=275963"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=275963"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=275963"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}