Splunk: Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands

Splunk: Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands

Critical Splunk Enterprise Vulnerability Exposes Systems to Unauthenticated Command Execution

Splunk has disclosed a critical vulnerability (CVE-2026-76268) in Splunk Enterprise, allowing unauthenticated attackers to execute operating-system commands via an exposed Patroni REST API. The flaw, rated 9.8 on the CVSS v3.1 scale, affects search head cluster members running vulnerable versions in the 10.4 and 10.2 branches specifically, releases before 10.4.3 and 10.2.7. The 10.0.x and 9.4.x branches are unaffected.

The vulnerability stems from missing authentication in the Patroni interface, enabling attackers with network access to the API to exploit the flaw without requiring a Splunk account or user interaction. Unlike typical Splunk Web access, exploitation hinges on exposure of the Patroni REST API, a key distinction for assessing risk in deployed environments.

Discovered by Splunk researcher Gabriel Nitu, the advisory does not confirm active exploitation or provide a public proof of concept, though the flaw presents a severe unauthenticated command-execution risk.

Alongside CVE-2026-76268, Splunk’s advisory details 16 additional vulnerabilities, including one high-severity (CVE-2026-76266) and 15 medium-severity issues. The high-severity flaw permits local attackers operating as the Splunk service account to manipulate installation content, triggering root-level command execution during a subsequent Linux package upgrade. Other vulnerabilities expose search queries, job metadata, private SPL2 module definitions, and Observability Cloud API tokens via server-side request forgery (CVE-2026-76274). Secure Gateway flaws enable unauthorized payload signing or modification of alert and mobile-device recipient data, though these require authenticated access or specific capabilities.

Splunk recommends upgrading to fixed versions (10.4.3, 10.2.7, 10.0.10, or 9.4.15) to address all 17 CVEs. For CVE-2026-76268, organizations not using Edge Processor, OpAmp, or SPL2 data pipelines can mitigate the risk by disabling the Patroni API via configuration. Additional remediation steps are required for four other flaws, including Secure Gateway upgrades or disabling affected apps where updates are not feasible.

Source: https://cyberpress.org/critical-splunk-enterprise-vulnerability/

Splunk cybersecurity rating report: https://www.rankiteo.com/company/splunk

"id": "SPL1791448034",
"linkid": "splunk",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology/Enterprise Software',
                        'name': 'Splunk Enterprise',
                        'type': 'Software'}],
 'attack_vector': 'Network Access to Patroni REST API',
 'description': 'Splunk has disclosed a critical vulnerability '
                '(CVE-2026-76268) in Splunk Enterprise, allowing '
                'unauthenticated attackers to execute operating-system '
                'commands via an exposed Patroni REST API. The flaw affects '
                'search head cluster members running vulnerable versions in '
                'the 10.4 and 10.2 branches (releases before 10.4.3 and '
                '10.2.7). The vulnerability stems from missing authentication '
                'in the Patroni interface, enabling attackers with network '
                'access to exploit the flaw without requiring a Splunk account '
                'or user interaction. Alongside this, Splunk’s advisory '
                'details 16 additional vulnerabilities, including one '
                'high-severity and 15 medium-severity issues.',
 'impact': {'operational_impact': 'Unauthenticated command execution, '
                                  'potential system compromise',
            'systems_affected': 'Splunk Enterprise (search head cluster '
                                'members running versions before 10.4.3 and '
                                '10.2.7)'},
 'post_incident_analysis': {'corrective_actions': 'Patch management, '
                                                  'configuration hardening, '
                                                  'and disabling unused '
                                                  'services',
                            'root_causes': 'Missing authentication in Patroni '
                                           'REST API, exposure of vulnerable '
                                           'components'},
 'recommendations': 'Upgrade to patched versions, disable unused APIs, monitor '
                    'for exploitation attempts, and apply additional '
                    'remediation steps for other disclosed vulnerabilities.',
 'references': [{'source': 'Splunk Advisory'}],
 'response': {'containment_measures': 'Upgrade to fixed versions (10.4.3, '
                                      '10.2.7, 10.0.10, or 9.4.15); disable '
                                      'Patroni API if not in use',
              'remediation_measures': 'Apply patches, disable vulnerable '
                                      'components, upgrade Secure Gateway or '
                                      'disable affected apps'},
 'title': 'Critical Splunk Enterprise Vulnerability Exposes Systems to '
          'Unauthenticated Command Execution',
 'type': 'Vulnerability Exploitation',
 'vulnerability_exploited': 'CVE-2026-76268'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.