<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>File-Manipulation on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/file-manipulation/</link><description>Recent content in File-Manipulation on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 18 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/file-manipulation/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-20253: Splunk Enterprise Auth Bypass Flaw</title><link>https://zxcloudsecurity.co.uk/posts/splunk-enterprise-missing-authentication-cve-2026-20253/</link><pubDate>Thu, 18 Jun 2026 00:00:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/splunk-enterprise-missing-authentication-cve-2026-20253/</guid><description>CVE-2026-20253 is a critical Splunk Enterprise vulnerability allowing unauthenticated file creation or truncation via a PostgreSQL sidecar endpoint. Patch</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CISA Known Exploited Vulnerabilities</a></p>
<hr>
<p>A critical vulnerability in Splunk Enterprise allows unauthenticated attackers to create or delete arbitrary files via an exposed PostgreSQL sidecar service endpoint that lacks proper authentication controls. This could enable attackers to corrupt data, disrupt logging pipelines, or potentially escalate to full system compromise. It is listed on the CISA Known Exploited Vulnerabilities catalogue, confirming active exploitation in the wild.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Immediately apply Splunk&rsquo;s patch ahead of the 21 June 2026 remediation deadline, and in the interim restrict network access to the PostgreSQL sidecar service endpoint using firewall rules or security group policies so it is not reachable from untrusted networks.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">CVE-2026-20253: Splunk Enterprise</a></p>
]]></content:encoded></item></channel></rss>