Splunk Patched an Unauthenticated RCE in Its Own SIEM — Here's What You Need to Know
An unauthenticated attacker with network access to a Splunk search head cluster member can execute arbitrary OS commands. No credentials. No interaction. CVE-2026-76268 | CVSS 9.1 | Affects 10.4.x and 10.2.x only What's vulnerable Splunk Enterprise ships with Patroni — a PostgreSQL high-availability tool — running a REST API on search head cluster members. That API has no authentication on…
An unauthenticated attacker with network access to a Splunk search head cluster member is able to execute arbitrary operating system commands, without requiring any credentials or interaction, according to CVE-2026-76268. This vulnerability affects Splunk Enterprise versions 10.4.x and 10.2.x only. Splunk Enterprise includes Patroni, a PostgreSQL high-availability tool, which runs a REST API on search head cluster members.
This API lacks authentication for critical operations, making it vulnerable to exploitation via network access.
The affected versions range from 10.4.0 to 10.4.2 for Splunk 10.x, and from 10.2.0 to 10.2.6 for Splunk 10.2.x. Versions 10.0.x and 9.4.x are not impacted. Compromising a Splunk deployment goes beyond a mere breach, as it creates a blind spot for attackers. With command execution on a search head, adversaries can suppress or delete alerts, modify detection rules and saved searches, exfiltrate all logs collected by Splunk, and pivot to other systems using Splunk's extensive network access.
In the interim, should a patch not be feasible, a workaround exists: set disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf, then restart Splunk. However, this workaround is only viable if Edge Processor, OpAmp, or SPL2 data pipelines are not in use. If these features are employed, patching is the only recommended solution.
The CVE disclosure encompasses 17 individual vulnerabilities across all four branches of Splunk (10.4, 10.2, 10.0, and 9.4), including CVE-2026-76266 (7.7) involving local user privilege escalation, CVE-2026-76270 (6.5) addressing SQL injection in the SPL2 module filtering (only affecting Splunk 10.4), CVE-2026-76274 (6.5) concerning SSRF in the Splunk App for Observability Cloud leading to API token leakage, and CVE-2026-76286 (5.3) dealing with SSRF in the Splunk MCP Server, which discloses authentication tokens to attacker-controlled hosts. The recommended fixes are Splunk versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.