Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise
Summary
| CVE | CVE-2026-76268 |
|---|---|
| State | PUBLISHED |
| Assigner | cisco |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-07 21:17:17 UTC |
| Updated | 2026-10-09 04:18:12 UTC |
| Description | In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation. Splunk Enterprise versions 10.0.x and 9.4.x are not affected. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.004000000 probability, percentile 0.321120000 (date 2026-10-08)
Problem Types: CWE-306 | CWE-306 The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Splunk | Splunk Enterprise | affected 10.4 10.4.3 custom | Not specified |
| CNA | Splunk | Splunk Enterprise | affected 10.2 10.2.7 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| advisory.splunk.com/advisories/SVD-2026-1001 | [email protected] | advisory.splunk.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Gabriel Nitu, Splunk (en)
Additional Advisory Data
Solutions
CNA: Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.
Workarounds
CNA: Turn off the PostgreSQL sidecar by setting `disabled = true` in the `[postgres]` stanza of `$SPLUNK_HOME/etc/system/local/server.conf` if you do not use Edge Processor, OpAmp, or SPL2 data pipelines. Restart Splunk Enterprise to apply the change. For more information see [Sidecar configuration settings](https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) and [server.conf](https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/configuration-file-reference/10.2.7-configuration-file-reference/server.conf) in the Splunk documentation.