CISA added a critical Splunk Enterprise vulnerability to its Known Exploited Vulnerabilities catalog on June 18, ordering federal agencies to patch affected systems by Sunday, June 21 under Binding Operational Directive 26-04.
The flaw, tracked as CVE-2026-20253, carries a CVSSv3.1 score of 9.8 (Critical). Splunk's security advisory SVD-2026-0603 documents that versions 10.2.0 through 10.2.3 and 10.0.0 through 10.0.6 are affected; versions 9.4 and earlier are not, and Splunk Cloud Platform is also not affected because it does not use PostgreSQL sidecars. The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to create or truncate arbitrary files on the system without credentials.
Splunk patched the flaw with versions 10.2.4 and 10.0.7 earlier this month. Exploitation pressure escalated quickly after the fix: on June 12, security research firm WatchTowr published a detailed technical write-up alongside proof-of-concept exploit code, warning that the unauthenticated endpoint is reachable for remote code execution. Splunk updated its advisory on June 18 to confirm limited in-the-wild exploitation, urging customers to upgrade immediately. CISA's KEV listing the same day converted that urgency into a formal government mandate for the U.S. federal civilian enterprise.
The exposure footprint is measurable. Internet security watchdog Shadowserver tracks more than 1,400 internet-exposed Splunk instances, with 952 in North America and 223 in Europe. No count of how many of those run the vulnerable 10.2.x or 10.0.x branches is publicly available, but any instance reachable over the network without a firewall filter is a potential target.
For administrators who cannot upgrade before the Sunday deadline, Splunk offers a workaround in its advisory: disable the PostgreSQL sidecar service by adding disabled = true under the [postgres] stanza in $SPLUNK_HOME/etc/system/local/server.conf, then restart the service. Disabling PostgreSQL breaks Edge Processor, OpAmp, and SPL2 data pipelines on the same instance; core search, indexing, and dashboard functionality remain intact. Administrators running any of those pipeline features should treat the upgrade path as non-optional.
The Sunday deadline shows how quickly CISA is applying BOD 26-04, issued last week: a 9.8-rated flaw with confirmed exploitation and a public proof-of-concept qualifies for the shortest remediation window the directive allows. Private-sector organizations running Splunk for security operations or log aggregation should treat the CISA mandate as a strong signal to accelerate their own patch schedules, even absent a legal obligation to match the federal timeline.













