TL;DR
Splunk has released two advisories that fix 22 Splunk Enterprise vulnerabilities across four supported branches. The worst, CVE-2026-76268, lets an unauthenticated attacker run operating-system commands through the Patroni REST API, with a CVSS score of 9.8. Admins should upgrade to 10.4.3, 10.2.7, 10.0.10 or 9.4.15.
- Total: 22 CVEs
- Severity: 1 Critical Β· 1 High Β· 15 Medium Β· 5 Unrated
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical Β· CVSSv3) β CVE-2026-76268
- Action: Apply the latest security updates now
Too many Splunk alerts in your inbox? Switch to one weekly digest, sorted by severity.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-76268 | 9.8 | CWE-306 | 10.4.3, 10.2.7 | Not exploited |
| CVE-2026-76266 | 7.7 | CWE-269 | 10.4.3, 10.2.7, 10.0.10 (+1) | Not exploited |
| CVE-2026-76265 | 6.5 | CWE-284 | 10.4.3, 10.2.7, 10.0.10 (+4) | Not exploited |
| CVE-2026-76269 | 6.5 | CWE-639 | 10.4.3, 10.2.7, 10.0.10 (+1) | Not exploited |
| CVE-2026-76270 | 6.5 | CWE-89 | 10.4.3 | Not exploited |
| CVE-2026-76271 | 6.5 | CWE-407 | 10.4.3, 10.2.7, 10.0.10 | Not exploited |
| CVE-2026-76274 | 6.5 | CWE-918 | 10.4.3, 10.2.7, 10.0.10 | Not exploited |
| CVE-2026-76280 | 6.3 | CWE-732 | 10.4.3, 10.2.7, 10.0.10 (+4) | Not exploited |
Why It Matters
Splunk Enterprise sits at the center of many security operations centers. It collects logs, runs searches and drives alerts. As a result, an attacker who controls a Splunk server could read sensitive data or blind defenders.
The two advisories cover different ground. The first, SVD-2026-1001, lists 17 individual flaws. The second, SVD-2026-1002, is a hardening release that groups internally found bugs into five CVE IDs by weakness class. The advisories do not report any exploitation in the wild or a public proof-of-concept.
How the Attacks Work
Patroni REST API Command Execution (CVE-2026-76268)
Newer Splunk releases run a PostgreSQL sidecar that is managed through Patroni. According to Splunk, an unauthenticated user with network access to that API “on a search head cluster member could execute attacker-controlled operating-system commands.” The cause is simple. Splunk says the interface “does not require authentication for critical configuration operations.”
Other Individual Flaws
CVE-2026-76266 (CVSS 7.7) allows local privilege escalation during Linux package upgrades. The remaining 15 bugs rate Medium. They include an SQL injection in the SPL2 module catalog, an SSRF in the Splunk App for Splunk Observability Cloud and several REST API access control gaps. Several also affect Splunk Secure Gateway. For example, CVE-2026-76269 involves improper access control when retrieving search jobs through the REST API. Separately, CVE-2026-76271 can trigger a denial of service in the Discover Splunk Observability Cloud app.
Hardening Release
The hardening advisory groups its findings by weakness type. CVE-2026-76281 covers improper access control and carries the top score of 9.8. Meanwhile, CVE-2026-76284 covers improper neutralization at 9.0, and CVE-2026-76282 covers resource lifetime issues at 8.8. Splunk notes that each score “is the highest CVSS score among those findings.” The CVE records show that Splunk found these issues internally.
Affected Versions
These Splunk Enterprise vulnerabilities affect four branches:
- 10.4.0 to 10.4.2, fixed in 10.4.3
- 10.2.0 to 10.2.6, fixed in 10.2.7
- 10.0.0 to 10.0.9, fixed in 10.0.10
- 9.4.0 to 9.4.14, fixed in 9.4.15
The critical Patroni flaw hits only 10.4 and 10.2. Splunk states that “versions 10.0.x and 9.4.x are not affected” by it.
Patch and Mitigation Steps
Upgrade to a fixed release first. However, an upgrade alone will not close every issue. Splunk says four CVEs need extra steps: CVE-2026-76264, CVE-2026-76265, CVE-2026-76272 and CVE-2026-76280. Check each CVE page for the required action.
If you cannot patch right away, Splunk offers a workaround for the Patroni bug. Turn off the PostgreSQL sidecar in server.conf if you do not use Edge Processor, OpAmp or SPL2 data pipelines, then restart Splunk. In addition, restrict network access to search head cluster members until the Splunk Enterprise vulnerabilities are patched.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!