AI analysis
CVE-2026-76268 is a missing-authentication flaw in Splunk Enterprise that lets an unauthenticated remote attacker run operating-system commands. It is triggered by network access to the Patroni REST API on a search head cluster member, because that interface does not require authentication for critical configuration operations and accepts attacker-controlled commands. Successful exploitation yields full command execution on the affected cluster member with high impact to confidentiality, integrity, and availability (CVSS 3.1 9.8). Affected products are Splunk Enterprise versions below 10.4.3 and below 10.2.7; versions 10.0.x and 9.4.x are not affected. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade Splunk Enterprise on the affected release lines to 10.4.3 or later, or to 10.2.7 or later. Until patched, restrict network access to the Patroni REST API on search head cluster members so it is reachable only from trusted management hosts, and review those members for unexpected configuration or process changes. Splunk Enterprise 10.0.x and 9.4.x are not affected.
Affected
| Splunk Enterprise | versions below 10.4.3 and below 10.2.7 (10.0.x and 9.4.x are not affected) |
Estimated exposure
moderatelow thousands of search-head-cluster members potentially affected; internet-exposed count unknown — Splunk Enterprise is a widely deployed enterprise SIEM, historically on the order of about 10,000 customer organizations, but this flaw applies only to search head cluster members on the stated version lines whose Patroni REST API is…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation. Splunk Enterprise versions 10.0.x and 9.4.x are not affected.