Splunk Patches Critical 9.8 Flaw Allowing Unauthenticated Remote Command Execution
Splunk patched CVE-2026-76268, a CVSS 9.8 flaw allowing unauthenticated command execution via Patroni.
Splunk patched CVE-2026-76268, disclosed October 7, 2026, a CWE-306 missing-authentication flaw in the Patroni REST API on Splunk Enterprise search head cluster members. Scored CVSS 9.8, it could allow a network attacker to run operating-system commands without credentials or user interaction. Versions before 10.4.3 in the 10.4 branch and before 10.2.7 in the 10.2 branch are affected; 10.0.x and 9.4.x are not affected by this CVE. Splunk credits Gabriel Nitu, reports no evidence of exploitation, and separately published SVD-2026-1002, whose CVE-2026-76281 also scores 9.8.
- CVE-2026-76268 is unauthenticated command execution scored CVSS 9.8.
- Missing authentication affects the Patroni REST API on search head cluster members.
- Splunk Enterprise 10.4.3 and 10.2.7 fix the affected branches.
- No in-the-wild exploitation is reported; a conditional sidecar workaround exists.
- Separate advisory SVD-2026-1002 includes CVSS 9.8 issue CVE-2026-76281.
Vulnerabilities mentionedAll →
- CVE-2026-762689.8—Unauthenticated command execution via Splunk Patroni APIpublished · Splunk Enterprise+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-76268+1 related CVE | Unauthenticated command execution via Splunk Patroni API CVE-2026-76268 is a missing-authentication flaw in Splunk Enterprise that lets an unauthenticated remote attacker run operating-system commands. It is triggered by network access to the Patroni REST API on a search head cluster member, because that interface does not require authentication for critical configuration operations and accepts attacker-controlled commands. Successful exploitation yields full command execution on the affected cluster member with high impact to confidentiality, integrity, and availability (CVSS 3.1 9.8). Affected products are Splunk Enterprise versions below 10.4.3 and below 10.2.7; versions 10.0.x and 9.4.x are not affected. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article538 words · extracted from cybersecuritynews.com · click to collapse
Splunk has released security updates to fix a critical Splunk Enterprise vulnerability that could let an attacker run operating system commands without logging in. Tracked as CVE-2026-76268, the flaw carries a CVSS v3.1 score of 9.8 and was disclosed on October 7, 2026.
It affects the Patroni REST API on search head cluster members, where missing authentication leaves critical configuration operations exposed to attackers with network access.
Splunk documents the issue in security advisory SVD-2026-1001. Splunk Enterprise versions in the 10.4 branch before 10.4.3 and the 10.2 branch before 10.2.7 are affected.
The vendor explicitly states that versions 10.0.x and 9.4.x are not affected by this particular vulnerability, an important distinction when reviewing the wider October patch release.
The weakness stems from an interface that does not require authentication before allowing critical configuration changes. An attacker who can reach the Patroni REST API on an affected search head cluster member could use that access to execute attacker-controlled commands on the host.
The vulnerability is classified as CWE-306: Missing Authentication for a Critical Function. Network access is the key requirement. The disclosure does not mean every Splunk installation can be attacked directly from the internet; exposure depends on whether an attacker can reach the affected interface.
However, it requires no account privileges or user interaction. The published score also rates attack complexity as low, with high potential impact on data confidentiality, integrity, and service availability.
Splunk Patches Critical Flaw
Splunk credits its researcher Gabriel Nitu with discovering the issue internally. The public record explains the missing authentication but does not provide a detailed exploit sequence. Its severity score describes the potential risk, rather than proving that attackers have already used the flaw against live systems.
Administrators running affected branches should upgrade to Splunk Enterprise 10.4.3 or 10.2.7, or later releases. Teams should check the version and configuration of each relevant cluster member rather than treating a single updated server as proof that the entire deployment is protected.
For deployments that cannot update immediately, Splunk provides a conditional workaround: turn off the PostgreSQL sidecar if Edge Processor, OpAmp, and SPL2 data pipelines are not used. Set disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf, then restart Splunk Enterprise.
Administrators should review the linked sidecar configuration documentation before applying this change because the workaround depends on which features the deployment uses.
Splunk also published SVD-2026-1002, covering internally identified weaknesses fixed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. This hardening advisory groups findings under five CVE identifiers rather than describing one command execution flaw. Its separate access control group, CVE-2026-76281, also reaches a maximum score of 9.8.
The distinction matters: older branches remain part of the broader update effort even though they are not affected by CVE-2026-76268. Readers can also review Cybersecuritynews.com’s earlier coverage of a Splunk Enterprise pre-authentication RCE chain and Splunk’s August security patches for related context. Those reports cover separate flaws and should not be treated as evidence of exploitation of this newly disclosed issue.
Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.