Security1 publisherNot yet confirmed elsewhere2 min readPublished
Splunk's Patroni API flaw lets unauthenticated attackers run commands on search head clusters
Splunk fixed 22 Enterprise CVEs on October 7, led by a 9.8 unauthenticated command flaw in the Patroni REST API. Sites without Edge Processor, OpAmp or SPL2 pipelines can switch off the PostgreSQL sidecar now, but a second 9.8 still needs the upgrade.
The Watch · Security desk

What happened
- The Patroni flaw affects two of the four release lines Splunk patched, 10.4 and 10.2, and only search head cluster members on those lines.
- CVE-2026-76266, rated 7.7, lets a user who can execute commands under the Splunk account leave content behind that runs as root the next time Splunk is upgraded through a Linux package; upgrading from the tar file avoids it.
- Three Secure Gateway flaws, two of which let non-admins make the app sign attacker-controlled payloads, are fixed in Secure Gateway 3.10.11, 3.9.25 and 3.8.72.
- CVE-2026-76264, scripted lookup edits by non-admins, also needs scripted_lookup_raw_write_enforcement = block under [lookup] in limits.conf and a restart.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Every 10.2 or 10.4 search head cluster now has to establish whether it uses Edge Processor, OpAmp or SPL2 pipelines, because that answer decides whether the sidecar can go off before the upgrade.
- constraint The sidecar change buys time against one of the two 9.8s only, and the upgrade is the only fix the report documents for CVE-2026-76281, so the change window cannot be skipped.
- exposure On hosts where the Splunk account may already be compromised, patching through the Linux package can run planted content as root, so those hosts are safer upgraded from the tar file.
The flaw is CWE-306, missing authentication [2]. Critical configuration operations on the Patroni REST API require no login, so an attacker with network access to that interface can run operating-system commands on the cluster member [3]. How exploitable it is depends on who can reach that interface [3].
To turn off the PostgreSQL sidecar, set disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf and restart Splunk [5]. The guidance applies to organizations that do not use Edge Processor, OpAmp or SPL2 data pipelines [5]. A cluster that runs any of the three has to take the upgrade to 10.4.3 or 10.2.7 [5][11].
That setting deals with one of the two 9.8s in the set [18]. The other, CVE-2026-76281, comes from SVD-2026-1002, which groups Splunk's internally identified findings by weakness class and scores each CVE by its worst finding [10]. The report identifies it only by class, CWE-284, and by score [10]. Two more CVEs in that advisory score 9.0 and 8.8 [10][19]. Nobody should assume a setting aimed at the Patroni interface covers any of them [5][10]. The fixed builds are 10.4.3, 10.2.7, 10.0.10 and 9.4.15, or later [11].
The 10.4 line also has a bug of its own: CVE-2026-76270, a 6.5 SQL injection in the SPL2 module catalog [14]. CVE-2026-76274, a 6.5 server-side request forgery, can disclose the Observability Cloud API token [15]. Admins who do not use Splunk Mobile, Spacebridge or Mission Control can disable Secure Gateway instead of updating it [9]. Where an upgrade is blocked, removing run_collect from roles without internal-index access mitigates CVE-2026-76279 [13].
A security bulletin issued October 9 rated the overall risk as medium, even though it listed remote code execution among the possible outcomes, according to The Cyber Express [6]. The report does not mention exploitation in the wild, a public proof of concept, or any actor tied to these bugs [16].
What to watch
- Published component and precondition details for CVE-2026-76281, the internal 9.8 that the sidecar guidance does not mention.
- A public proof of concept or reported scanning against the Patroni REST API on Splunk search head clusters.
- A known-exploited listing for CVE-2026-76268 that puts a remediation date on the upgrade.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Splunk patched 22 CVE identifiers in Splunk Enterprise, CVE-2026-76264 through CVE-2026-76285, described in two advisories, SVD-2026-1001 and SVD-2026-1002, both published on October 7, 2026.
- [2]
The most severe flaw, CVE-2026-76268, carries a CVSSv3.1 score of 9.8 and is a CWE-306 missing-authentication weakness in the Patroni REST API.
- [3]
On a search head cluster member running a version below 10.4.3 or 10.2.7, an unauthenticated attacker with network access to the Patroni REST API could run operating-system commands, because critical configuration operations require no login.
- [5]
Organizations that do not use Edge Processor, OpAmp or SPL2 data pipelines can turn off the PostgreSQL sidecar by setting disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf, then restarting.
- [6]
A security bulletin issued on October 9, 2026 rated the overall risk as medium and warned that a remote attacker could exploit some of the flaws to achieve remote code execution, denial of service, elevation of privilege, security restriction bypass, sensitive information disclosure and data manipulation.
- [7]
CVE-2026-76266 (CVSS 7.7, High) lets a local user who can run commands as the Splunk account plant content that a later Linux package upgrade executes as root; upgrading with a tar file avoids the issue.
- [8]
Three Splunk Secure Gateway flaws: CVE-2026-76265 (6.5) and CVE-2026-76272 (4.3) let non-admin users make it sign attacker-controlled payloads, and CVE-2026-76280 (6.3) allows writes to alert and mobile-device recipient data; they are fixed in Secure Gateway 3.10.11, 3.9.25 and 3.8.72.
- [9]
Admins who do not use Splunk Mobile, Spacebridge or Mission Control can disable the Secure Gateway app instead.
- [10]
Advisory SVD-2026-1002 groups internal findings by weakness class, scoring each CVE by its worst finding: CVE-2026-76281 (CWE-284, 9.8), CVE-2026-76284 (CWE-707, 9.0), CVE-2026-76282 (CWE-664, 8.8), CVE-2026-76283 (CWE-693, 7.6) and CVE-2026-76285 (CWE-710, 4.4).
- [11]
Splunk advises upgrading Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15, or later.
- [12]
CVE-2026-76264 (scripted lookup edits by non-admins), CVE-2026-76265, CVE-2026-76272 and CVE-2026-76280 need extra steps; for CVE-2026-76264, admins should set scripted_lookup_raw_write_enforcement = block under [lookup] in limits.conf and restart.
- [13]
Where upgrading is not possible, removing run_collect from roles without internal-index access mitigates CVE-2026-76279.
- [14]
CVE-2026-76270 (CVSS 6.5) is a SQL injection in the SPL2 module catalog affecting only 10.4.x.
- [15]
CVE-2026-76274 (CVSS 6.5), an SSRF, can disclose the Observability Cloud API token.
- [16]
The Cyber Express report on the Splunk fixes does not mention exploitation in the wild, a public proof of concept, or a threat actor associated with the vulnerabilities.
- [17]
CVE-2026-76268 affects two of the four release lines Splunk patched (10.4 and 10.2); the 10.0 and 9.4 lines are unaffected.
- [18]
The 22-CVE set contains two CVEs scored 9.8: CVE-2026-76268 and CVE-2026-76281.
- [19]
Three of the five SVD-2026-1002 CVEs score 8.8 or higher (9.8, 9.0, 8.8).
Sources
1 independent publisher whose own reporting we read for this story.
- thecyberexpress.comSplunk Patches 22 Vulnerabilities, Including Critical Flaw With CVSS 9.8
1 article · October 9, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.