Subscribe

Social Media Links

Insights

 | 3 minute read

Ankura CTIX FLASH Update – June 16, 2026



, stems from missing authentication controls on a PostgreSQL sidecar service, enabling any network-accessible user to interact with, backup, and restore recovery endpoints without credentials. Security researchers demonstrated that attackers can exploit these endpoints to import malicious PostgreSQL database dumps, leverage a local .pgpass file to authenticate to Splunk’s internal database, and execute attacker-controlled SQL during the restore process. By abusing PostgreSQL’s lo_export function, adversaries can write arbitrary files to the Splunk file system and overwrite Python scripts that Splunk executes regularly, resulting in pre-authenticated RCE. The vulnerability affects Splunk Enterprise versions 10.0.0–10.0.6 and 10.2.0–10.2.3, with fixes available in versions 10.0.7 and 10.2.4, while Splunk Enterprise 10.4 and Splunk Cloud are not affected. In addition to , Splunk patched multiple other vulnerabilities, including high-severity flaws that could enable RCE, server-side request forgery (SSRF), and cross-site scripting (XSS), as well as medium-severity issues in Splunk Enterprise and Splunk SOAR that could allow sensitive data exfiltration, saved search ownership reassignment, or log injection attacks. Separately, Palo Alto Networks addressed several vulnerabilities across its portfolio, including the high-severity affecting Cortex XSOAR and Cortex XSIAM, which could allow attackers to access and modify restricted resources due to improper credential validation in the CommvaultSecurityIQ integration. Although neither vendor has reported active exploitation of these vulnerabilities, the public release of technical details for significantly raises the risk of opportunistic attacks, making prompt patching and exposure assessments a priority for affected organizations.

📧 Never Miss a Briefing

Stay informed and secure. Subscribe to Ankura’s Cyber Flash Update, a bi-weekly briefing curated by our top cybersecurity experts. Receive timely insights on emerging threats, vulnerabilities and malicious actors to keep your systems secure. 

Join the Cyber Flash Update community today.


© Copyright 2026. The views expressed herein are those of the author(s) and not necessarily the views of Ankura Consulting Group, LLC., its management, its subsidiaries, its affiliates, or its other professionals. Ankura is not a law firm and cannot provide legal advice.

Let’s Connect

We solve problems by operating as one firm to deliver for our clients. Where others advise, we solve. Where others consult, we partner.

I’m interested in
I need help with