Splunk released two security advisories addressing 17 vulnerabilities in Splunk Enterprise and associated components, including CVE-2026-76268, a critical missing-authentication flaw in the Patroni REST API on search head cluster members. Attackers with network access to the affected interface can execute operating system commands without credentials or user interaction. The flaw affects Enterprise 10.4.0–10.4.2 and 10.2.0–10.2.6; the 10.0.x and 9.4.x branches are explicitly unaffected by this vulnerability. The additional disclosures cover privilege escalation, SQL injection, denial of service, access-control failures, information disclosure, and server-side request forgery that can expose authentication tokens, with hardening updates spanning all four branches.
Administrators should upgrade affected search head cluster members to 10.4.3 or 10.2.7, apply the relevant fixes for other affected branches and components, and restrict network access to the Patroni API. Where immediate patching is not possible and the specified features are unused, Splunk provides a conditional workaround to disable the PostgreSQL sidecar. Severity reporting differs between the references: one cites 9.1, while another reports a CVSS v3.1 score of 9.8 for the critical flaw. At publication, reporting identified no known public proof-of-concept exploit or active exploitation and stated that the vulnerability was not in CISA’s Known Exploited Vulnerabilities catalog.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-1018 covering Splunk Enterprise and Splunk MCP Server, referencing the previously unrecorded MCP Server advisory SVD-2026-1004. It urged administrators to review Splunk's advisories and apply necessary updates, without specifying MCP Server versions or technical vulnerability details.
Splunk published advisories SVD-2026-1001 and SVD-2026-1002 covering vulnerabilities in Splunk Enterprise and associated components. The disclosures included critical Patroni remote command execution, privilege escalation, SQL injection, denial of service, access-control failures, information disclosure, and token-exposing SSRF weaknesses.
Splunk released fixes in Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15 for the applicable vulnerabilities. The Patroni flaw is fixed in 10.4.3 and 10.2.7; the 10.0.x and 9.4.x branches are unaffected by that specific vulnerability.
Splunk identified the disclosed vulnerabilities internally and credited researcher Gabriel Nitu with discovering CVE-2026-76268. The flaw allows attackers with network access to the Patroni REST API on affected search head cluster members to execute operating system commands without authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourceacn.gov.it
Open sourcecybersecuritynews.com
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.