# CISA flags Splunk Enterprise auth bypass under exploit

Published: 2026-06-18 · Severity: high · Sectors: government-national
Canonical: https://vorant.io/reports/3dc753b2-24c9-5e29-a9a6-178f36afd17b/cisa-flags-splunk-enterprise-auth-bypass-under-exploit

> CISA added CVE-2026-20253, a missing authentication flaw in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation.

CISA has added CVE-2026-20253 to its Known Exploited Vulnerabilities Catalog following confirmation of active exploitation in the wild. The vulnerability is a missing authentication for critical function issue affecting Splunk Enterprise, allowing attackers to bypass authentication controls. This vulnerability class is a frequent attack vector that poses significant risk to federal agencies and the broader enterprise.

Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch agencies are required to prioritize rapid remediation of KEV Catalog vulnerabilities on publicly exposed assets, particularly those that grant total control post-exploitation. The directive also establishes requirements for agencies to assess whether systems were compromised prior to patching. While the directive is mandatory only for federal agencies, CISA urges all organizations to adopt risk-based vulnerability management practices and prioritize remediation of cataloged vulnerabilities.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20253 (KEV)

Source reporting: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-adds-one-known-exploited-vulnerability-catalog

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/3dc753b2-24c9-5e29-a9a6-178f36afd17b/cisa-flags-splunk-enterprise-auth-bypass-under-exploit.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
