Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands
Splunk patched CVE-2026-76268, a CVSS 9.8 flaw letting unauthenticated attackers run OS commands via the Patroni API.
Splunk advisory SVD-2026-1001, published October 7, 2026, covers CVE-2026-76268, a CVSS 9.8 missing-authentication flaw (CWE-306) in the Patroni REST API on a search head cluster member. A remote unauthenticated attacker can run operating-system commands without user interaction. Affected releases are Splunk Enterprise 10.4 before 10.4.3 and 10.2 before 10.2.7; branches 10.0.x and 9.4.x are not affected, and Splunk reports no active exploitation. Fixes are in 10.4.3 and 10.2.7; some deployments can set disabled = true under the [postgres] stanza and restart.