Cyber & AI intelligence
Wasteland.
Briefs indexed3048
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-76268 2026-10-07

CVE-2026-76268: Unauthenticated Command Execution via Patroni REST API in Splunk Enterprise

"A critical (CVSS 9.8) missing-authentication flaw in Splunk Enterprise lets an unauthenticated attacker with network access to the Patroni REST API on a search head cluster member run operating-system commands of their…"

A critical (CVSS 9.8) missing-authentication flaw in Splunk Enterprise lets an unauthenticated attacker with network access to the Patroni REST API on a search head cluster member run operating-system commands of their choosing.

What Is It

CVE-2026-76268 is a missing-authentication-for-critical-function weakness (CWE-306) in Splunk Enterprise. The Patroni Representational State Transfer (REST) Application Programming Interface (API) on search head cluster members doesn't require authentication for critical configuration operations. An unauthenticated user who can reach that interface over the network can use it to execute attacker-controlled operating-system commands.

Splunk's documentation points to its Sidecar configuration settings for more context on this component. Cisco PSIRT ([email protected]) is the source of the CVE record, which was published to NVD on 2026-10-07. NVD lists its status as "Received."

Why It Matters

The CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H:

Search head clusters often sit at the center of security monitoring, so command execution on a cluster member is a serious exposure.

Exploitation status: CISA's Known Exploited Vulnerabilities (KEV) catalog contains no entry for this CVE, so KEV does not confirm active exploitation. The supplied sources don't mention any public exploit.

What's Vulnerable

Affected product: Splunk Enterprise, REST API module, on search head cluster members.

Branch Affected Status
10.4 Versions below 10.4.3 Affected
10.2 Versions below 10.2.7 Affected
10.0.x — Not affected
9.4.x — Not affected

The NVD record doesn't list any CPEs yet.

Patch Status

The affected ranges imply the fixes:

There's no CISA KEV entry, so CISA has not set a required action or due date. Read Splunk advisory SVD-2026-1001 for the vendor's official remediation guidance. Until you patch, check which hosts can reach the Patroni REST API on search head cluster members.

Sources