high Cve 2026 76268 · Exploits

Splunk Enterprise search head clusters exposed to critical unauthenticated RCE in Patroni API (CVE-2026-76268)

Splunk Enterprise search head clusters carry a critical unauthenticated RCE, CVE-2026-76268, CVSS 9.8
AK

Threat intelligence editor · Published Oct 7, 2026, 9:50 PM EDT

Splunk patched CVE-2026-76268, a CVSS 9.8 unauthenticated RCE in the Patroni API on search head cluster members. Fixed in 10.4.3 and 10.2.7; no exploitation stated.

Splunk has patched a critical flaw in Splunk Enterprise that lets an unauthenticated attacker with network access run operating-system commands on a search head cluster member. The bug, CVE-2026-76268, carries a CVSS 3.1 score of 9.8 as assigned by Splunk, and affects Splunk Enterprise 10.4.0 through 10.4.2 and 10.2.0 through 10.2.6. Fixes shipped in 10.4.3 and 10.2.7. Splunk's advisory does not say the flaw is being exploited, and it does not appear in CISA's Known Exploited Vulnerabilities catalog as of 8 October 2026.

What happened

Splunk published advisory SVD-2026-1001 on 7 October 2026, and the CVE record reached the National Vulnerability Database the same day. The advisory table lists 17 CVEs, from CVE-2026-76264 to CVE-2026-76280. CVE-2026-76268 is the only Critical one. CVE-2026-76266, a local privilege escalation through Linux package upgrades, is rated High at 7.7. The rest are Medium.

Splunk describes CVE-2026-76268 as missing authentication for a critical function (CWE-306) in the Patroni REST API. An unauthenticated user with network access to that API on a search head cluster member could execute attacker-controlled commands, because the interface does not require authentication for critical configuration operations. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: network reachable, low complexity, no privileges, no user interaction. NVD has not yet analysed the record (status "Received") and shows only the Splunk-assigned score.

Why the sidecar matters: the June precedent

This is not the first critical missing-authentication bug in Splunk's PostgreSQL sidecar this year. CVE-2026-20253 (advisory SVD-2026-0603) was also CWE-306, also scored 9.8, and let an unauthenticated user create or truncate arbitrary files. It affected 10.2.0 to 10.2.3 and 10.0.0 to 10.0.6 and was fixed in 10.2.4 and 10.0.7. On 18 June 2026 Splunk added that its PSIRT "became aware of limited exploitation", and CISA added the CVE to its Known Exploited Vulnerabilities catalogue the same day (NVD).

CVE-2026-76268 is a different bug with a different impact, and Splunk makes no exploitation statement about it. But the June history is a reason not to wait for one. Attackers have already shown interest in this component, and unauthenticated on-premises flaws in widely deployed products tend to be probed fast, as with the SharePoint zero-day CVE-2026-56164 and the Cisco ISE zero-day CVE-2026-76460.

Timeline: June 2026 CVE-2026-20253 in Splunk's PostgreSQL sidecar, exploitation noted 18 June, then CVE-2026-76268 on 7 October

The same sidecar had an exploited critical flaw in June; Splunk makes no exploitation statement for the new one.

Who is affected

BranchAffectedFixed
10.410.4.0 to 10.4.210.4.3
10.210.2.0 to 10.2.610.2.7
10.0not affectedn/a
9.4not affectedn/a

The advisory ties the flaw to search head cluster members. Splunk's sidecar documentation shows the PostgreSQL storage sidecar, configured in the [postgres] stanza of server.conf, is on by default in Splunk Enterprise (disabled = false) and off by default in Splunk Cloud Platform (disabled = true). The advisory entry for this CVE names only Splunk Enterprise. In the June advisory's changelog, Splunk said Postgres sidecars are not used in Splunk Cloud and that Splunk Cloud was not affected by that vulnerability. That statement is about the June CVE, not this one.

How to check exposure

  • Confirm the version of every Splunk Enterprise instance. Anything on 10.4.0 to 10.4.2 or 10.2.0 to 10.2.6 is in scope.
  • Identify which of those hosts are search head cluster members.
  • On those hosts, check whether the [postgres] stanza in server.conf has disabled = true. Use splunk btool server list postgres --debug to see the effective value and the file that sets it.
  • Find the Patroni port. Per the sidecar configuration page the advisory links, the Patroni service address is postgres:patroni:address in the [ipc_broker] stanza of server.conf. If it is not set, the IPC Broker assigns a random port. Splunk's example pins it to 8008, but that is an example, not a default. Run splunk btool server list ipc_broker --debug as well as the postgres check.
  • Check which network segments can reach that port on those hosts.

Patch or workaround

Patch first. Upgrade to 10.4.3 or 10.2.7 or later. The advisory's general remediation also lists 10.0.10 and 9.4.15, but those branches are not affected by this CVE.

If you cannot upgrade immediately, Splunk offers one workaround: turn off the PostgreSQL sidecar by setting disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf, then restart Splunk Enterprise. Splunk conditions this on not using Edge Processor, OpAmp or SPL2 data pipelines. If you use any of them, the workaround would break them, so network restriction becomes the fallback. In the June advisory Splunk said that turning off Postgres leaves core search, indexing and dashboards unaffected, though it can cascade to dependent sidecar processes. Our reading of the same sidecar page is that the Edge Processor control-plane and OpAmp sidecars are available on single search heads, which needs enable_clustered_mode = false in [postgres], so on cluster members the trade-off is mainly SPL2 data pipelines. Limiting access to the affected API to trusted management hosts is our inference from the attack precondition (network access), not a Splunk-published step.

Credit: the advisory attributes the finding to Gabriel Nitu of Splunk, so it was found internally. We found no public proof of concept or researcher write-up. That can change quickly for a 9.8 unauthenticated bug, so treat patching as urgent even without a known exploit.

What is still unclear

  • Whether the vulnerable service is reachable only on clustered deployments or also on standalone search heads. The advisory says search head cluster member.
  • Whether Splunk Cloud Platform is affected by this CVE. Splunk said in June that sidecars are not used there, and this advisory lists only Splunk Enterprise, but it makes no Cloud statement of its own.
  • Whether Patroni binds beyond localhost on cluster members.
  • Whether exploitation has occurred. Splunk makes no statement and KEV has no entry; absence of both is not proof of safety.
  • NVD analysis and any independent scoring are pending.

Sources

Keep reading

All latest →
  1. watchExploitsNext.js Dev Server MCP Flaw CVE-2026-94486 Lets Malicious Sites Read Source Snippets and Logs5 min
  2. elevatedExploitsWindows Cross Device flaw gives local users SYSTEM, with a public PoC5 min
  3. criticalExploitsArista VeloCloud Orchestrator Exploited at CVSS 10.0, With No Fix Listed for Two Release Trains4 min
  4. criticalExploitsAdobe Commerce and Magento Authorization Flaw CVE-2026-71362 Now Exploited5 min
  5. criticalExploitsShinyHunters Exploits Oracle PeopleSoft CVE-2026-35273 via WAF Bypass5 min
  6. highExploitsZyxel GS1900 switch overflow exploited on 996 devices, now in CISA KEV4 min