Impact
A lack of authentication on the PostgreSQL sidecar service endpoint allows a remote, unauthenticated user to create or truncate any file on the host. This flaw enables an attacker to write arbitrary files or delete existing ones without credentials, providing a path for persistent footholds or disabling system services. The weakness is a missing authentication control (CWE-306).
Affected Systems
Splunk Enterprise versions 10.2 and lower than 10.2.4, and 10 and lower than 10.0.7, are affected. Versions 9.4 and earlier are not impacted.
Risk and Exploitability
The CVSS score of 9.8 reflects the high impact and ease of exploitation. The EPSS score of 96% indicates a very high likelihood of exploitation in the field. Because no authentication controls exist, the vulnerability can be exercised by any network‑reachable user, and it is listed in the CISA KEV catalog, signalling active exploitation.
OpenCVE Enrichment