NCSC-2026-0198 [1.01] [M/H] Vulnerabilities fixed in Splunk Enterprise and Splunk Cloud Platform
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Splunk has fixed multiple vulnerabilities in Splunk Enterprise and Splunk Cloud Platform. The vulnerabilities affect various components of Splunk Enterprise and Splunk Cloud Platform. Splunk has assessed the vulnerability with CVE-2026-20253 in the PostgreSQL sidecar service endpoint as critical, allowing unauthenticated users to create or delete arbitrary files due to the lack of authentication controls. Another vulnerability with CVE-2026-20251 concerns Remote Code Execution (RCE) via unsafe deserialization of KV Store data with the 'jsonpickle' Python library, allowing low-privileged users without admin or power roles to execute code remotely. Furthermore, multiple vulnerabilities have been identified that allow sensitive data to be exfiltrated via SSRF, CSS injection, and XSS attacks. Due to insufficient validation of URLs, domains, and user input, attackers can bypass security controls, access internal systems, and exfiltrate data. Update: The Splunk Product Security Incident Response Team (PSIRT) reports that limited and targeted exploitation of the vulnerability with CVE-2026-20253 has been observed. The vulnerability allows a malicious actor to create or delete files, disrupting the operation of the system. As far as known, code execution is not possible.
CSIRTS triage
- What
- Multiple vulnerabilities allow unauthenticated access and remote code execution.
- Who is affected
- Users of Splunk Enterprise and Splunk Cloud Platform.
- Urgency
- Remediation is urgent due to the critical nature of the vulnerabilities and active exploitation.
- Action
- Apply the latest security updates from Splunk.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Splunk Enterprise and Splunk Cloud Platform
Get an email when a new Splunk Enterprise and Splunk Cloud Platform advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0198
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-20253Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2026-2025132.2% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 98% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20253 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20251 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownexploitedSplunk security advisory (AV26-586) – Update 1cccs
- criticalexploitedCVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function Vulnerabilitycisa-kev
Recent advisories for Splunk Enterprise and
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0322 [1.00] [M/H] Vulnerabilities fixed in Splunk Enterprise by Splunkncsc-nl · 2026-08-21
- high[NEW] [high] Splunk Splunk Enterprise: Multiple vulnerabilitiescert-bund · 2026-08-20
- mediumCVE-2026-76390: In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthentic…nvd · 2026-08-19
- highCVE-2026-76388: In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk En…nvd · 2026-08-19
- highCVE-2026-76387: In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Secur…nvd · 2026-08-19
- highCVE-2026-76355: In Splunk Enterprise 10.4 versions below 10.4.2, an unauthenticated user could retrieve the in…nvd · 2026-08-19
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21