Splunk Enterprise (CVE-2026-20253): Unauthenticated Pre-Auth RCE via PostgreSQL Sidecar - 1,400+ Exposed Instances, CISA KEV
CVE-2026-20253 (CVSS 9.8) is an unauthenticated pre-auth RCE in Splunk Enterprise: HTTP endpoints on the PostgreSQL sidecar allow arbitrary file write leading…