CVE-2026-20253 Runs as the splunk User — and That’s the Index You’d Hunt It In
An unauthenticated file-write in Splunk Enterprise’s bundled Postgres sidecar chains to code execution as the splunk service account — the same account that owns your _audit and _internal indexes. The detection problem is mostly a log-forwarding hygiene problem you either solved last year or didn’t.