CVE-2026-20253 CrowdStrike LogScale · LogScale

Detect CVE-2026-20253: Splunk Enterprise Missing Authentication for Critical Function in CrowdStrike LogScale

Detects exploitation attempts targeting CVE-2026-20253, a missing authentication vulnerability (CWE-306) in Splunk Enterprise. This KEV-listed vulnerability allows unauthenticated access to critical Splunk functions. Attackers may leverage this to execute searches, exfiltrate data, or manipulate Splunk configurations without valid credentials.

MITRE ATT&CK

Tactic
Initial Access Persistence Collection

LogScale Detection Query

CrowdStrike LogScale (LogScale)
cql
#event_simpleName=NetworkConnectIP4
| DestinationPort in (8000, 8089, 9997, 8088)
| HttpUrl = "/services/search/jobs*" OR HttpUrl = "/services/data/inputs*" OR HttpUrl = "/services/admin*" OR HttpUrl = "/services/authentication*" OR HttpUrl = "/en-US/splunkd/__raw/services*"
| NOT (HttpRequestHeaders = "*Authorization: Splunk*" OR HttpRequestHeaders = "*Authorization: Bearer*" OR HttpCookieHeader = "*splunkd_*")
| HttpMethod in ("POST", "GET", "DELETE", "PUT")
| stats count() as request_count, values(HttpUrl) as accessed_paths, values(HttpMethod) as methods by RemoteAddressIP4, LocalAddressIP4, DestinationPort
| where request_count > 1
| sort -request_count
critical severity medium confidence

CrowdStrike CQL query correlating network connection events to Splunk ports with unauthenticated HTTP requests to critical API paths, identifying potential exploitation of CVE-2026-20253.

Data Sources

CrowdStrike Falcon Network EventsDNS RequestsProcess Network Connections

Required Tables

NetworkConnectIP4

False Positives & Tuning

  • Falcon sensor on Splunk hosts may generate noise from internal Splunk process communications
  • Authorized red team or penetration testing activities targeting Splunk infrastructure
  • Splunk cluster peer-to-peer communications appearing as unauthenticated in some views
  • Third-party SIEM integrations polling Splunk via legacy API patterns without modern auth

Other platforms for CVE-2026-20253


Testing Methodology

Validate this detection against 4 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Unauthenticated Splunk Search Job Creation via REST API

    Expected signal: HTTP POST to port 8089 without Authorization header; Splunk web_access.log entry with null/anonymous user; network flow record to TCP/8089

  2. Test 2Unauthenticated Splunk User Enumeration via REST API

    Expected signal: HTTP GET to /services/authentication/users on port 8089 without credentials; response body containing user list if vulnerable

  3. Test 3Unauthenticated Splunk Index Listing and Data Access

    Expected signal: Sequential unauthenticated GET and POST requests to Splunk REST API; multiple different /services/ paths accessed from same source IP within short timeframe

  4. Test 4Unauthenticated Splunk Configuration Modification Attempt

    Expected signal: HTTP POST to /services/data/inputs/ without Authorization header; Splunk audit log entry for configuration change with anonymous user context

Unlock Pro Content

Get the full detection package for CVE-2026-20253 including response playbook, investigation guide, and atomic red team tests.

Response PlaybookInvestigation GuideHunting QueriesAtomic Red Team TestsTuning Guidance

Related Detections