Splunk Patches Critical 9.8 Flaw Allowing Unauthenticated Remote Command Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Splunk has released security updates to fix a critical Splunk Enterprise vulnerability that could let an attacker run operating system commands without logging in. Tracked as CVE-2026-76268, the flaw carries a CVSS v3.1 score of 9.8 and was disclosed on October 7, 2026.

It affects the Patroni REST API on search head cluster members, where missing authentication leaves critical configuration operations exposed to attackers with network access.

Splunk documents the issue in security advisory SVD-2026-1001. Splunk Enterprise versions in the 10.4 branch before 10.4.3 and the 10.2 branch before 10.2.7 are affected.

The vendor explicitly states that versions 10.0.x and 9.4.x are not affected by this particular vulnerability, an important distinction when reviewing the wider October patch release.

The weakness stems from an interface that does not require authentication before allowing critical configuration changes. An attacker who can reach the Patroni REST API on an affected search head cluster member could use that access to execute attacker-controlled commands on the host.

The vulnerability is classified as CWE-306: Missing Authentication for a Critical Function. Network access is the key requirement. The disclosure does not mean every Splunk installation can be attacked directly from the internet; exposure depends on whether an attacker can reach the affected interface.

However, it requires no account privileges or user interaction. The published score also rates attack complexity as low, with high potential impact on data confidentiality, integrity, and service availability.

Splunk Patches Critical Flaw

Splunk credits its researcher Gabriel Nitu with discovering the issue internally. The public record explains the missing authentication but does not provide a detailed exploit sequence. Its severity score describes the potential risk, rather than proving that attackers have already used the flaw against live systems.

Administrators running affected branches should upgrade to Splunk Enterprise 10.4.3 or 10.2.7, or later releases. Teams should check the version and configuration of each relevant cluster member rather than treating a single updated server as proof that the entire deployment is protected.

For deployments that cannot update immediately, Splunk provides a conditional workaround: turn off the PostgreSQL sidecar if Edge Processor, OpAmp, and SPL2 data pipelines are not used. Set disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf, then restart Splunk Enterprise.

Administrators should review the linked sidecar configuration documentation before applying this change because the workaround depends on which features the deployment uses.

Splunk also published SVD-2026-1002, covering internally identified weaknesses fixed in versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. This hardening advisory groups findings under five CVE identifiers rather than describing one command execution flaw. Its separate access control group, CVE-2026-76281, also reaches a maximum score of 9.8.

The distinction matters: older branches remain part of the broader update effort even though they are not affected by CVE-2026-76268. Readers can also review Cybersecuritynews.com’s earlier coverage of a Splunk Enterprise pre-authentication RCE chain and Splunk’s August security patches for related context. Those reports cover separate flaws and should not be treated as evidence of exploitation of this newly disclosed issue.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Splunk Patches Critical 9.8 Flaw Allowing Unauthenticated Remote Command Execution appeared first on Cyber Security News.