Description
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation.

Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Published: 2026-10-07
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An unauthenticated user with network access to the Patroni REST API in Splunk Enterprise can execute arbitrary operating‑system commands because the endpoint does not require authentication for critical configuration operations. This flaw is classified as CWE‑306, a missing‑authentication weakness, and allows an attacker to gain full control over the Splunk host, compromising confidentiality, integrity, and availability.

Affected Systems

Splunk Enterprise installations running any version below 10.4.3 or 10.2.7 are vulnerable; the vendor has fixed the issue in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 or later. Versions 10.0.x and 9.4.x are explicitly not affected. The vulnerability is relevant to search head cluster members that expose the Patroni REST API.

Risk and Exploitability

The CVSS score of 9.8 places this vulnerability in the critical range. The EPSS score is not available, and it is not listed in KEV, but the lack of authentication for a privileged API suggests a high likelihood of exploitation as soon as the REST endpoint is reachable. The likely attack vector is an unauthenticated request to the API from a host that has network connectivity to the Splunk cluster, either through an internal network or via a misconfigured firewall. Successful exploitation would allow the attacker to execute arbitrary commands on the host, leading to a full compromise.

Generated by OpenCVE AI on October 7, 2026 at 23:30 UTC.

Remediation

Vendor Solution

Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.


Vendor Workaround

Turn off the PostgreSQL sidecar by setting `disabled = true` in the `[postgres]` stanza of `$SPLUNK_HOME/etc/system/local/server.conf` if you do not use Edge Processor, OpAmp, or SPL2 data pipelines. Restart Splunk Enterprise to apply the change. For more information see [Sidecar configuration settings](https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) and [server.conf](https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/configuration-file-reference/10.2.7-configuration-file-reference/server.conf) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk Enterprise to version 10.4.3, 10.2.7, 10.0.10, 9.4.15 or later to apply the vendor‑provided fix.
  • If a patch is not immediately available, edit $SPLUNK_HOME/etc/system/local/server.conf to set disabled = true under the [postgres] stanza, which disables the PostgreSQL sidecar that hosts the vulnerable API, then restart Splunk Enterprise.
  • Configure firewalls or network controls to restrict external access to the Patroni REST API so that only trusted internal hosts can reach the endpoint.

Generated by OpenCVE AI on October 7, 2026 at 23:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Enterprise
Vendors & Products Splunk
Splunk splunk Enterprise

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation. Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Title Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Splunk Splunk Enterprise
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:31.281Z

Reserved: 2026-08-19T12:02:03.620Z

Link: CVE-2026-76268

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:17.607

Modified: 2026-10-07T21:17:17.607

Link: CVE-2026-76268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function