CVE-2026-76268

LOWCVSS 9.8 · CRITICAL

Signal is active with 8 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation. Splunk Enterprise versions 10.0.x and 9.4.x are not affected.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 9 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 8 mentions on most recent observed day (2026-10-08)
  • 9 total mentions across 2 days

Deep dive

Activity timeline9 mentions / 2d
02468Mentions · 2026-10-07: 1Mentions · 2026-10-08: 810-0710-08
Referenced assets7 URLs
Full discourse9 posts
  • ThreatAft@ThreatAft

    🔐 SPLUNK — 22 CVEs, PEAK CVSS 9.8 CVE-2026-76268 (9.8) — unauth RCE via Patroni REST API on search head cluster members. Affects 10.4 and 10.2 only Fix: 10.4.3 / 10.2.7 / 10.0.10 / 9.4.15 🔗 https://threataft.com/articles/splunk-mass-disclosure-cve-2026-76268-patroni-rce?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #Splunk #CVE #SIEM #PatchNow

    0101054
    46 followersView on X
  • hi^^@collysucker

    https://advisory.splunk.com 5 new Security Advisories for Cisco Splunk Some of these are quite critical, e.g. CVE-2026-76281 & CVE-2026-76268 with each CVSS 9.8 #infosec #splunk

    0000150
    221 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - Splunk Enterprise Search Head Cluster Patroni REST Unauth RCE (CVE-2026-76268) Splunk Enterprise exposes the Patroni REST API on search head cluster members without auth, allowing unauthenticated network attackers to invoke critical config operations and execute attacker-controlled OS commands. Splunk Enterprise 10.0.x and 9.4.x are not affected. 👉Affected: Splunk Enterprise < 10.4.3 and < 10.2.7 | Upgrade to 10.4.3 / 10.2.7

    0000044
    312 followersView on X
  • The Daily Tech Feed@dailytechonx

    Splunk just addressed a critical flaw (CVE-2026-76268) in its Enterprise app that allows unauthenticated remote command execution via the Patroni REST API. If running versions before 10.4.3 or 10.2.7, upgrade now. Backup deployments may temporarily disable the PostgreSQL sidecar—but verify you’re not using features like Edge Processor, OpAmp or SPL2 pipelines. #NetworkSecurity #Splunk #RCE #Patroni #Vulnerability #Patch #Splunk #RCE #Cybersecurity #Vulnerability #Patroni #SecurityPatch https://thedailytechfeed.com/splunk-urgent-patch-for-remote-command-execution-flaw/

    0000060
    788 followersView on X
  • NEXSIGHT@NEXSIGHTNEWS

    Splunk Enterpriseの17件の脆弱性を修正 — Patroni REST APIの認証欠落でOS命令実行の恐れ(CVE-2026-76268、CVSS 9.8) https://cyber.nexsight.co/articles/2026/10/08/splunk-enterprise-svd-2026-1001-patroni-unauth-rce-2026-10-08/

    0000045
    76 followersView on X
  • takenaka hiroya@Joe_Biden_ja

    Splunk Enterprise の Patroni REST API に認証が無く、未認証で OS コマンドを実行される CVE-2026-76268(CVSS 9.8)。修正版は 10.4.3 / 10.2.7。上げられない間の塞ぎ方もまとめました。 https://cve.autoarticles.net/cve/CVE-2026-76268

    0000042
    556 followersView on X
  • Atlas Threat Monitoring@ThreatAtlas

    Unpatched vulnerabilities don't stay hidden on our atlas. #CVE CRITICAL VULNERABILITY DETECTED CVE ID → CVE-2026-76268 Vendor → Unknown Severity → Critical — CVSS 9.8 Product → Unknown Date → 2026-10-07 A critical vulnerability (Missing Authentication for Critical Function) has been disclosed affecting Unknown. Patch immediately. Powered by @Brandefense #ThreatIntel #CyberSecurity #CVE #Unknown

    0000042
    451 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now. #Splunk #SplunkEnterprise #SIEM #CVE202676268 #CVE202676281 #RCE #PatchNow #Vulnerability https://securityonline.info/splunk-enterprise-vulnerabilities-october-2026/

    00000310
    13.0K followersView on X
  • VulniPulse@vulnipulse

    CVE advisory (CRITICAL): CVE-2026-76268 - splunk: Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise. https://vulnipulse.com/advisories/splunk-cve-2026-76268 #CVE #CyberSecurity #Splunk #SplunkEnterprise

    0000031
    7 followersView on X

Explore more