CVE-2026-20253: Critical RCE in Splunk Enterprise EITW

Last Updated: June 26, 2026 5:29 PM

What’s Happening

CVSSv3: 9.8

Splunk initially published this vulnerability June 10th, 2026. It has been found EITW. A patch is available. It can also be mitigated by disabling the PostgreSQL sidecar service. A technical analysis was performed by watchTowr Labs and they published a report and POC on Friday, June 12th. Splunk subsequently updated their advisory June 18th after they became aware of exploitation in the wild.

Splunk’s Advisory:

watchTowr’s Analysis:

Actions

Update to the latest version of Splunk. Disable PostgreSQL sidecar service if it’s not necessary.

Notes

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36088

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-20253

https://www.cve.org/CVERecord?id=CVE-2026-20253