Splunk Security Updates – 11 June 2026

Splunk has released security updates to address several vulnerabilities affecting multiple Splunk products.

The addressed vulnerabilities could allow the attacker to perform server-side request forgery (SSRF), conduct cross-site scripting (XSS) attacks, manipulate data, bypass security restrictions, obtain sensitive information, or execute arbitrary code on the affected systems.

Sample of the addressed vulnerabilities:

1. Splunk Enterprise Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint Vulnerability (CVE-2026-20253):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Data Manipulation

2. Splunk Secure Gateway Remote Code Execution through Deserialization of Untrusted Data Vulnerability (CVE-2026-20251):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Remote Code Execution

The affected products:

  • Splunk SOAR.
  • Splunk Enterprise.
  • Splunk Secure Gateway.
  • Splunk Cloud Platform.
Vulnerabilities
  • CVE-2026-20260
  • CVE-2026-20259
  • CVE-2026-20258
  • CVE-2026-20257
  • CVE-2026-20256
  • CVE-2026-20255
  • CVE-2026-20254
  • CVE-2026-20253
  • CVE-2026-20252
  • CVE-2026-20251
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Splunk Security Updates

References