elastic
high
kql
Splunk Enterprise PostgreSQL Recovery Endpoint Injection Artifacts
Detects CVE-2026-20253 exploit artifacts against the Splunk Enterprise PostgreSQL sidecar recovery endpoints via
complementary signals. Where endpoint or Network Packet Capture request-body logging is available, the rule matches
PostgreSQL connection-string injection keywords, suspicious `backupFile` destinations, and known filesystem artifacts
used to pivot from backup/restore primitives to file write or RCE. It also detects vulnerable recovery endpoint probing
and empty-password Basic auth cre