Splunk patches critical Patroni flaw; Canada widens alerts
Splunk fixed CVE-2026-76268 (CVSS 9.8); Canada's October 8 advisory also urges updates for broader Enterprise builds and MCP Server.
Splunk patched CVE-2026-76268, disclosed October 7, 2026 in advisory SVD-2026-1001, a CWE-306 missing-authentication flaw in the Patroni REST API on Splunk Enterprise search head cluster members. Scored CVSS 9.8, it lets a remote attacker run operating-system commands without credentials or user interaction. Cyber Security News and GBHackers say 10.4 before 10.4.3 and 10.2 before 10.2.7 are affected, while 10.0.x and 9.4.x are not affected by this CVE; fixes are 10.4.3 and 10.2.7, Splunk reports no active exploitation, and Gabriel Nitu is credited. GBHackers says some deployments can set disabled = true under the [postgres] stanza and restart, which Cyber Security News describes only as a conditional sidecar workaround. Only Cyber Security News also mentions separate advisory SVD-2026-1002 and CVSS 9.8 issue CVE-2026-76281. On October 8, the Canadian Centre for Cyber Security issued AV26-1018 on vulnerabilities known as of October 7, citing SVD-2026-1001 and SVD-2026-1004 and listing Enterprise builds before 10.0.10, 10.2.7, 10.4.3, and 9.4.15 plus Splunk MCP Server before 1.2.1—broader than the other reports' scope for CVE-2026-76268 alone—while also reporting no active exploitation.
- CVE-2026-76268, disclosed October 7, 2026 in Splunk advisory SVD-2026-1001, is a CVSS 9.8 CWE-306 missing-authentication flaw in the Patroni REST API on Splunk Enterprise search head cluster members.
- A remote attacker can run operating-system commands without credentials or user interaction; Splunk credits Gabriel Nitu and reports no active exploitation.
- For this CVE, Splunk Enterprise 10.4 before 10.4.3 and 10.2 before 10.2.7 are affected; 10.0.x and 9.4.x are not, and fixes are 10.4.3 and 10.2.7.
- GBHackers says some deployments can set disabled = true under the [postgres] stanza and restart; Cyber Security News calls this only a conditional sidecar workaround.
- Only Cyber Security News also cites separate advisory SVD-2026-1002 and CVSS 9.8 issue CVE-2026-76281.
- On October 8, 2026, Canada's Cyber Centre issued AV26-1018 for vulnerabilities known as of October 7, citing SVD-2026-1001 and SVD-2026-1004, listing Enterprise builds before 10.0.10, 10.2.7, 10.4.3, and 9.4.15 plus Splunk MCP Server…
Coverage timelineoldest first · each row is one article
- · 18h agoSplunk Patches Critical 9.8 Flaw Allowing Unauthenticated Remote Command Execution
Cyber Security News· 74
Splunk patched CVE-2026-76268, a CVSS 9.8 flaw allowing unauthenticated command execution via Patroni.
- · 16h agoCritical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands
GBHackers· 72
Splunk patched CVE-2026-76268, a CVSS 9.8 flaw letting unauthenticated attackers run OS commands via the Patroni API.
- · 11h agoSplunk security advisory (AV26-1018)
Canadian Centre for Cyber Security· 38
Vulnerabilities in this storyAll →
- CVE-2026-762689.8—Unauthenticated command execution via Splunk Patroni APIpublished · Splunk Enterprise+1 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-76268+1 related CVE | Unauthenticated command execution via Splunk Patroni API CVE-2026-76268 is a missing-authentication flaw in Splunk Enterprise that lets an unauthenticated remote attacker run operating-system commands. It is triggered by network access to the Patroni REST API on a search head cluster member, because that interface does not require authentication for critical configuration operations and accepts attacker-controlled commands. Successful exploitation yields full command execution on the affected cluster member with high impact to confidentiality, integrity, and availability (CVSS 3.1 9.8). Affected products are Splunk Enterprise versions below 10.4.3 and below 10.2.7; versions 10.0.x and 9.4.x are not affected. It is not listed in CISA KEV, and no public proof-of-concept is known. |