Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-76268: Splunk Enterprise lets unauthenticated users run commands via API
CVE-2026-76268 · published 2 days ago
Summary
In certain older versions of Splunk Enterprise, anyone with network access to the Patroni REST API on a search head cluster member could send commands that the operating system would execute, because the API does not require a login for critical settings. This could let an attacker take control of the server or disrupt its operation. Upgrade to version 10.4.3 or later (or 10.2.7 or later) to ensure the API requires authentication.
What to do
- Update splunk splunk enterprise to version 10.4.3 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| splunk | splunk enterprise | < 10.4.3 |
Original advisory text
Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation.
Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta