An unauthenticated attacker with network access to a Splunk search head cluster member can execute arbitrary OS commands. No credentials. No interaction.
CVE-2026-76268 | CVSS 9.1 | Affects 10.4.x and 10.2.x only
What's vulnerable
Splunk Enterprise ships with Patroni — a PostgreSQL high-availability tool — running a REST API on search head cluster members. That API has no authentication on critical operations. Network access is enough.
Affected: 10.4.0–10.4.2 and 10.2.0–10.2.6.
Not affected: 10.0.x and 9.4.x.
Why a SIEM RCE is especially bad
A compromised Splunk deployment isn't just a breach — it's a blind spot. Attackers with command execution on a search head can:
- Suppress or delete alerts
- Modify detection rules and saved searches
- Exfiltrate every log your org has shipped to Splunk
- Pivot to other systems via Splunk's broad network access
The workaround (if you can't patch yet)
An unauthenticated attacker with network access to a Splunk search head cluster member can execute arbitrary OS commands. No credentials. No interaction.
CVE-2026-76268 | CVSS 9.1 | Affects 10.4.x and 10.2.x only
What's vulnerable
Splunk Enterprise ships with Patroni — a PostgreSQL high-availability tool — running a REST API on search head cluster members. That API has no authentication on critical operations. Network access is enough.
Affected: 10.4.0–10.4.2 and 10.2.0–10.2.6.
Not affected: 10.0.x and 9.4.x.
Why a SIEM RCE is especially bad
A compromised Splunk deployment isn't just a breach — it's a blind spot. Attackers with command execution on a search head can:
- Suppress or delete alerts
- Modify detection rules and saved searches
- Exfiltrate every log your org has shipped to Splunk
- Pivot to other systems via Splunk's broad network access
The workaround (if you can't patch yet)
Set disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf, then restart Splunk.
Only safe to do if you're not using Edge Processor, OpAmp, or SPL2 data pipelines. If you are — patch first, no workaround.
The rest of the disclosure
17 CVEs total across all four branches (10.4, 10.2, 10.0, 9.4):
- CVE-2026-76266 (7.7) — local user runs commands as Splunk service account on Linux → loads attacker-controlled shared library → privilege escalation
- CVE-2026-76270 (6.5) — SQL injection in SPL2 module filtering, 10.4 only
- CVE-2026-76274 (6.5) — SSRF in Splunk App for Observability Cloud → leaks API token
- CVE-2026-76286 (5.3) — SSRF in Splunk MCP Server leaks auth token to attacker-controlled host
Fixed versions: 10.4.3, 10.2.7, 10.0.10, 9.4.15
Quick checklist
bash
# Check your version
splunk version
# Apply workaround if not on 10.4/10.2 with pipelines in use
echo "[postgres]
disabled = true" >> $SPLUNK_HOME/etc/system/local/server.conf
splunk restart
https://threataft.com/articles/splunk-mass-disclosure-cve-2026-76268-patroni-rce
Top comments (0)