Splunk Enterprise PostgreSQL Sidecar Pre-Auth RCE (CVE-2026-20253) | MSSP Advisory
CriticalHigh Confidence
DateJune 12, 2026
CVECVE-2026-20253
CVSS Score9.8
Risk Assessment
Client Exposure:High
Briefing Priority:Scheduled
Barrier to Entry:Low
📋Executive Summary
CVE-2026-20253 is a pre-authentication remote code execution vulnerability in Splunk Enterprise affecting the PostgreSQL Sidecar Service endpoint, which ships enabled by default on Splunk Enterprise deployed on AWS. An unauthenticated attacker can reach the internal PostgreSQL API through the main Splunk web interface on port 8000, abuse the backup and restore endpoints to achieve arbitrary file write as the splunk user, and then overwrite a Python script that Splunk executes regularly to gain full RCE. The CVSS score is 9.8 and a public detection artifact generator has already been released by watchTowr.
⚠️Why It Matters for MSSPs
If you or any of your clients run Splunk Enterprise on AWS, that instance is exploitable right now by anyone who can reach port 8000, no credentials required. Splunk is frequently the SIEM sitting at the center of a client security program, meaning an attacker who owns it owns the log pipeline, the alert logic, and potentially the credentials stored inside it. If a client gets hit through this and you had not told them about a 9.8 pre-auth RCE on their SIEM, that conversation with them will be very short and very final.
✅Recommended Action
Audit every client environment and your own stack for Splunk Enterprise on AWS right now, confirm whether the PostgreSQL Sidecar Service is running by checking for the process on port 5435, apply Splunk's patch for versions 10 and above immediately, and send a direct written advisory to any client running Splunk before end of business today.
🔒Get your first advisory free →
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.