CVE-2026-20252PoC(splunk / splunk)

MEDIUMCVSS 7.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch splunk splunk systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privileged user that does not hold the "admin" or "power" Splunk roles could send server-side requests to arbitrary internal destinations through the Dashboard Studio PDF export feature. The vulnerability exists because the trusted-domain validation uses a prefix match that can be bypassed with attacker-controlled subdomains (for example, docs.splunk.com.evil.com), and because the PDF export service follows HTTP redirects automatically without re-validating each redirect target against the allowlist.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • splunk
  • splunk_cloud_platform

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-17); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
splunksplunk_cloud_platform

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-17: 1Mentions · 2026-07-03: 1PoC Mentioned / Linked · 2026-06-17: 1Exploit Tool / Code · 2026-06-17: 1Patch / Workaround · 2026-06-17: 1Technical Details · 2026-06-17: 106-1707-03
Signal classification2 categories
PoC
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-171
PoC1
2026-07-031
Disclosure1
Full discourse2 posts
  • yousukezan@yousukezan
    PoC

    認証不要でSplunkサーバーを乗っ取れる深刻な脆弱性CVE-2026-20253のPoCが公開された。SplunkのPostgreSQLサイドカー機能を悪用し、ファイル作成からリモートコード実行まで可能になるため、SIEM基盤全体への侵害につながる恐れがある。 CVE-2026-20253は2026年6月10日に公開されたSVD-2026-0603で修正された脆弱性で、CVSSスコアは9.8。Splunk Enterpriseに同梱されるPostgreSQLサイドカーサービスのファイル操作用エンドポイントに認証が存在せず、攻撃者はネットワーク経由で任意のファイル作成や既存ファイルの切り詰めを実行できる。 研究者によると、この機能とPostgreSQLのlo_export関数を組み合わせることで、Splunkサービスが後に実行する場所へ悪意あるスクリプトを書き込み、認証なしでリモートコード実行に到達できる。Orca SecurityとNetSPIがこの攻撃チェーンを文書化し、6月13日にはGitHubでPoCが公開された。 影響を受けるのはSplunk Enterprise 10.0.6以前の10.0系、10.2.3以前の10.2系、および一部のSplunk Cloud Platform。修正版はSplunk Enterprise 10.2.4、10.0.7、10.4.0、9.4.12、9.3.13などで提供されている。 同アドバイザリではCVE-2026-20251、CVE-2026-20252、CVE-2026-20258も修正されたが、認証不要でサーバー侵害に直結しPoCも公開済みのCVE-2026-20253が最優先とされる。Splunkは回避策は存在しないとしており、修正適用までの間はサイドカーサービスへのネットワークアクセス制限が推奨されている。 https://latesthackingnews.com/2026/06/17/splunk-cve-2026-20253-postgresql-sidecar-rce/

    Post summary

    A proof‑of‑concept for CVE‑2026‑20253, featuring authentication‑less remote code execution via PostgreSQL side‑car, has been publicly released on GitHub. Splunk has issued patches for vulnerable versions and recommends temporary network isolation until updates are applied.

    010641.8K
    14.8K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Splunk ❗ CVE-2026-20253 ❗ CVE-2026-20252 ❗ CVE-2026-20251 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-splunk-6/ https://t.co/Qr17pq0lUL

    Post summary

    The message announces three CVE identifiers for Splunk products and links to external resources for more information, without providing evidence of PoC, exploit code, active attacks, or patches.

    00000232
    6.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksplunk---
Appsplunksplunk_cloud_platform---

Explore more