CVE-2026-20253: Splunk's PostgreSQL Sidecar Hands Out Shells. No Credentials Required
A CVSS 9.8 pre-authentication RCE in Splunk Enterprise's PostgreSQL sidecar service lets any network-reachable attacker chain file-write primitives into full code execution, with active exploitation reported within five days of disclosure.