Skip to content

Security1 publisherNot yet confirmed elsewhere2 min readPublished

Splunk's Patroni API flaw lets unauthenticated attackers run commands on search head clusters

Splunk fixed 22 Enterprise CVEs on October 7, led by a 9.8 unauthenticated command flaw in the Patroni REST API. Sites without Edge Processor, OpAmp or SPL2 pipelines can switch off the PostgreSQL sidecar now, but a second 9.8 still needs the upgrade.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Splunk's Patroni API flaw lets unauthenticated attackers run commands on search head clusters
Generated illustration

What happened

  • The Patroni flaw affects two of the four release lines Splunk patched, 10.4 and 10.2, and only search head cluster members on those lines.
  • CVE-2026-76266, rated 7.7, lets a user who can execute commands under the Splunk account leave content behind that runs as root the next time Splunk is upgraded through a Linux package; upgrading from the tar file avoids it.
  • Three Secure Gateway flaws, two of which let non-admins make the app sign attacker-controlled payloads, are fixed in Secure Gateway 3.10.11, 3.9.25 and 3.8.72.
  • CVE-2026-76264, scripted lookup edits by non-admins, also needs scripted_lookup_raw_write_enforcement = block under [lookup] in limits.conf and a restart.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Every 10.2 or 10.4 search head cluster now has to establish whether it uses Edge Processor, OpAmp or SPL2 pipelines, because that answer decides whether the sidecar can go off before the upgrade.
  • constraint The sidecar change buys time against one of the two 9.8s only, and the upgrade is the only fix the report documents for CVE-2026-76281, so the change window cannot be skipped.
  • exposure On hosts where the Splunk account may already be compromised, patching through the Linux package can run planted content as root, so those hosts are safer upgraded from the tar file.

The flaw is CWE-306, missing authentication [2]. Critical configuration operations on the Patroni REST API require no login, so an attacker with network access to that interface can run operating-system commands on the cluster member [3]. How exploitable it is depends on who can reach that interface [3].

To turn off the PostgreSQL sidecar, set disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf and restart Splunk [5]. The guidance applies to organizations that do not use Edge Processor, OpAmp or SPL2 data pipelines [5]. A cluster that runs any of the three has to take the upgrade to 10.4.3 or 10.2.7 [5][11].

That setting deals with one of the two 9.8s in the set [18]. The other, CVE-2026-76281, comes from SVD-2026-1002, which groups Splunk's internally identified findings by weakness class and scores each CVE by its worst finding [10]. The report identifies it only by class, CWE-284, and by score [10]. Two more CVEs in that advisory score 9.0 and 8.8 [10][19]. Nobody should assume a setting aimed at the Patroni interface covers any of them [5][10]. The fixed builds are 10.4.3, 10.2.7, 10.0.10 and 9.4.15, or later [11].

The 10.4 line also has a bug of its own: CVE-2026-76270, a 6.5 SQL injection in the SPL2 module catalog [14]. CVE-2026-76274, a 6.5 server-side request forgery, can disclose the Observability Cloud API token [15]. Admins who do not use Splunk Mobile, Spacebridge or Mission Control can disable Secure Gateway instead of updating it [9]. Where an upgrade is blocked, removing run_collect from roles without internal-index access mitigates CVE-2026-76279 [13].

A security bulletin issued October 9 rated the overall risk as medium, even though it listed remote code execution among the possible outcomes, according to The Cyber Express [6]. The report does not mention exploitation in the wild, a public proof of concept, or any actor tied to these bugs [16].

What to watch

  • Published component and precondition details for CVE-2026-76281, the internal 9.8 that the sidecar guidance does not mention.
  • A public proof of concept or reported scanning against the Patroni REST API on Splunk search head clusters.
  • A known-exploited listing for CVE-2026-76268 that puts a remediation date on the upgrade.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence60
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Splunk patched 22 CVE identifiers in Splunk Enterprise, CVE-2026-76264 through CVE-2026-76285, described in two advisories, SVD-2026-1001 and SVD-2026-1002, both published on October 7, 2026.

    ReportedSupportedView cited source
  2. [2]

    The most severe flaw, CVE-2026-76268, carries a CVSSv3.1 score of 9.8 and is a CWE-306 missing-authentication weakness in the Patroni REST API.

    ReportedSupportedView cited source
  3. [3]

    On a search head cluster member running a version below 10.4.3 or 10.2.7, an unauthenticated attacker with network access to the Patroni REST API could run operating-system commands, because critical configuration operations require no login.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. thecyberexpress.com

    1 article · October 9, 2026

    Splunk Patches 22 Vulnerabilities, Including Critical Flaw With CVSS 9.8

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories