DEV Community

threataft
threataft

Posted on

Splunk Patched an Unauthenticated RCE in Its Own SIEM — Here's What You Need to Know

An unauthenticated attacker with network access to a Splunk search head cluster member can execute arbitrary OS commands. No credentials. No interaction.

CVE-2026-76268 | CVSS 9.1 | Affects 10.4.x and 10.2.x only

What's vulnerable

Splunk Enterprise ships with Patroni — a PostgreSQL high-availability tool — running a REST API on search head cluster members. That API has no authentication on critical operations. Network access is enough.

Affected: 10.4.0–10.4.2 and 10.2.0–10.2.6.
Not affected: 10.0.x and 9.4.x.

Why a SIEM RCE is especially bad

A compromised Splunk deployment isn't just a breach — it's a blind spot. Attackers with command execution on a search head can:

  • Suppress or delete alerts
  • Modify detection rules and saved searches
  • Exfiltrate every log your org has shipped to Splunk
  • Pivot to other systems via Splunk's broad network access

The workaround (if you can't patch yet)

An unauthenticated attacker with network access to a Splunk search head cluster member can execute arbitrary OS commands. No credentials. No interaction.

CVE-2026-76268 | CVSS 9.1 | Affects 10.4.x and 10.2.x only

What's vulnerable

Splunk Enterprise ships with Patroni — a PostgreSQL high-availability tool — running a REST API on search head cluster members. That API has no authentication on critical operations. Network access is enough.

Affected: 10.4.0–10.4.2 and 10.2.0–10.2.6.
Not affected: 10.0.x and 9.4.x.

Why a SIEM RCE is especially bad

A compromised Splunk deployment isn't just a breach — it's a blind spot. Attackers with command execution on a search head can:

  • Suppress or delete alerts
  • Modify detection rules and saved searches
  • Exfiltrate every log your org has shipped to Splunk
  • Pivot to other systems via Splunk's broad network access

The workaround (if you can't patch yet)

Set disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf, then restart Splunk.

Only safe to do if you're not using Edge Processor, OpAmp, or SPL2 data pipelines. If you are — patch first, no workaround.

The rest of the disclosure

17 CVEs total across all four branches (10.4, 10.2, 10.0, 9.4):

  • CVE-2026-76266 (7.7) — local user runs commands as Splunk service account on Linux → loads attacker-controlled shared library → privilege escalation
  • CVE-2026-76270 (6.5) — SQL injection in SPL2 module filtering, 10.4 only
  • CVE-2026-76274 (6.5) — SSRF in Splunk App for Observability Cloud → leaks API token
  • CVE-2026-76286 (5.3) — SSRF in Splunk MCP Server leaks auth token to attacker-controlled host

Fixed versions: 10.4.3, 10.2.7, 10.0.10, 9.4.15

Quick checklist


bash
# Check your version
splunk version

# Apply workaround if not on 10.4/10.2 with pipelines in use
echo "[postgres]
disabled = true" >> $SPLUNK_HOME/etc/system/local/server.conf
splunk restart

 https://threataft.com/articles/splunk-mass-disclosure-cve-2026-76268-patroni-rce
Enter fullscreen mode Exit fullscreen mode

Top comments (0)