Splunk fixes critical flaws in Enterprise, including unauthenticated command execution

Splunk's October advisories patch dozens of issues in Splunk Enterprise, including CVE-2026-76268, a CVSS 9.8 flaw in the Patroni REST API that needs no authentication.

Splunk fixes critical flaws in Enterprise, including unauthenticated command execution

At a glance

  • CVE-2026-76268 (CVSS 9.8) lets unauthenticated attackers run OS commands via the Patroni REST API on search head cluster members
  • A hardening advisory adds CVE-2026-76281 (9.8) and CVE-2026-76284 (9.0) among five grouped findings
  • Fixed versions are Splunk Enterprise 10.4.3, 10.2.7, 10.0.10 and 9.4.15; Secure Gateway 3.10.11, 3.9.25 and 3.8.72
  • Splunk did not report any of the flaws as exploited in the wild

Splunk has released a set of security advisories fixing dozens of vulnerabilities in Splunk Enterprise and related apps, including a critical flaw that lets unauthenticated attackers execute operating system commands on some deployments. The advisories were published on October 7, and SecurityWeek reported that Splunk Enterprise received three critical-severity fixes that could allow command execution, unauthorized access and code injection.

What happened

According to Splunk's advisory SVD-2026-1001, the most serious issue is CVE-2026-76268 (CVSS 9.8), a missing-authentication bug in the Patroni REST API on search head cluster members that can lead to OS command execution. The advisory says only network access is required. The flaw affects Splunk Enterprise versions below 10.4.3 and 10.2.7; the 10.0.x and 9.4.x branches are not affected.

A separate hardening advisory, SVD-2026-1002, groups several findings under five CVEs, each scored by its most severe finding: CVE-2026-76281 (CVSS 9.8, improper access control), CVE-2026-76284 (9.0, improper neutralization), CVE-2026-76282 (8.8), CVE-2026-76283 (7.6) and CVE-2026-76285 (4.4). Splunk did not publish detailed descriptions for these.

Technical details

SVD-2026-1001 covers 17 CVEs in total. Besides the Patroni flaw, Splunk fixed CVE-2026-76266 (CVSS 7.7), in which the Linux package upgrade script trusts modifiable install content and can allow a local user to run commands as root. Medium-severity issues include missing authorization in Splunk Secure Gateway REST endpoints, an SQL injection in SPL2 module catalog filtering, an SSRF in the Observability app that can leak the configured API token, and several flaws exposing other users' search job data.

Other advisories address third-party package vulnerabilities in Splunk Enterprise and in the Splunk Add-on for Amazon Web Services (fixed in 8.2.2), and a medium-severity issue in Splunk MCP Server, CVE-2026-76286 (CVSS 5.3), fixed in version 1.2.1. Splunk's advisories do not state that any of the flaws have been exploited.

Who is affected

Splunk Enterprise 10.4.0–10.4.2, 10.2.0–10.2.6, 10.0.0–10.0.9 and 9.4.0–9.4.14 are affected by at least part of the fixes, according to the advisories. Organizations running search head clusters on the 10.4 and 10.2 branches face the highest risk because of the unauthenticated Patroni issue. Several flaws also affect Splunk Secure Gateway.

What to do

Splunk recommends upgrading Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15 or later, and Splunk Secure Gateway to 3.10.11, 3.9.25 or 3.8.72 or later. Where an immediate upgrade is not possible and Edge Processor, OpAmp or SPL2 pipelines are not used, the advisory says CVE-2026-76268 can be mitigated by setting disabled = true in the [postgres] stanza of server.conf and restarting. Administrators should also restrict network access to Splunk management interfaces.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.