A critical (CVSS 9.8) missing-authentication flaw in Splunk Enterprise lets an unauthenticated attacker with network access to the Patroni REST API on a search head cluster member run operating-system commands of their choosing.
What Is It
CVE-2026-76268 is a missing-authentication-for-critical-function weakness (CWE-306) in Splunk Enterprise. The Patroni Representational State Transfer (REST) Application Programming Interface (API) on search head cluster members doesn't require authentication for critical configuration operations. An unauthenticated user who can reach that interface over the network can use it to execute attacker-controlled operating-system commands.
Splunk's documentation points to its Sidecar configuration settings for more context on this component. Cisco PSIRT ([email protected]) is the source of the CVE record, which was published to NVD on 2026-10-07. NVD lists its status as "Received."
Why It Matters
The CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H:
- Network-reachable: no local access is needed.
- Low complexity: no special conditions are required.
- No privileges and no user interaction: an attacker needs no account and no one has to click anything.
- High impact: confidentiality, integrity and availability are all rated high.
Search head clusters often sit at the center of security monitoring, so command execution on a cluster member is a serious exposure.
Exploitation status: CISA's Known Exploited Vulnerabilities (KEV) catalog contains no entry for this CVE, so KEV does not confirm active exploitation. The supplied sources don't mention any public exploit.
What's Vulnerable
Affected product: Splunk Enterprise, REST API module, on search head cluster members.
| Branch | Affected | Status |
|---|---|---|
| 10.4 | Versions below 10.4.3 | Affected |
| 10.2 | Versions below 10.2.7 | Affected |
| 10.0.x | — | Not affected |
| 9.4.x | — | Not affected |
The NVD record doesn't list any CPEs yet.
Patch Status
The affected ranges imply the fixes:
- 10.4 branch: update to 10.4.3 or later.
- 10.2 branch: update to 10.2.7 or later.
There's no CISA KEV entry, so CISA has not set a required action or due date. Read Splunk advisory SVD-2026-1001 for the vendor's official remediation guidance. Until you patch, check which hosts can reach the Patroni REST API on search head cluster members.