Splunk October 2026 advisories: Splunk Enterprise 10.4.3, 10.2.7, 10.0.10 and 9.4.15 fix an unauthenticated command-execution flaw in the Patroni REST API on search head cluster members (CVE-2026-76268, CVSS 9.8) and more than 20 other issues
Splunk published five security advisories on 7 October 2026. SVD-2026-1001 lists 17 CVEs in Splunk Enterprise; the worst, CVE-2026-76268 (CVSS 3.1 9.8), affects 10.4 before 10.4.3 and 10.2 before 10.2.7: an unauthenticated attacker with network access to the Patroni REST API on a search head cluster member can run operating-system commands, because that interface does not require authentication for critical configuration operations. Versions 10.0.x and 9.4.x are not affected by that one. The same advisory also fixes a local privilege escalation to root through Linux package upgrades (CVE-2026-76266, 7.7), low-privilege access to other users' search jobs, queries and results (CVE-2026-76269, 6.5), SQL injection in the SPL2 module catalog (CVE-2026-76270, 6.5), an SSRF in the Splunk Observability Cloud app (CVE-2026-76274, 6.5) and several Splunk Secure Gateway authorisation gaps (CVE-2026-76265, 76272, 76280). SVD-2026-1002 groups internally found issues into five CVEs, the highest scored 9.8 (CVE-2026-76281, improper access control) and 9.0 (CVE-2026-76284, improper neutralisation). SVD-2026-1003 and SVD-2026-1005 cover third-party package updates in Splunk Enterprise and the Splunk Add-on for AWS, both rated Critical. SVD-2026-1004 fixes Splunk MCP Server before 1.2.1, which could send a user's Splunk authentication token to the URL of a custom API tool set up by another user (CVE-2026-76286, 5.3). Splunk does not report exploitation. Primary: Splunk security advisories.
- Product
- Splunk Enterprise (including Splunk Secure Gateway and the Splunk Observability Cloud apps), Splunk MCP Server, Splunk Add-on for Amazon Web Services
- Versions
- Splunk Enterprise 10.4.0 to 10.4.2, 10.2.0 to 10.2.6, 10.0.0 to 10.0.9 and 9.4.0 to 9.4.14 (CVE-2026-76268 only 10.4 and 10.2). Splunk Secure Gateway before 3.10.11, 3.9.25 and 3.8.72. Splunk MCP Server before 1.2.1.
- CVSS
- Critical (CVE-2026-76268 and CVE-2026-76281, CVSS 3.1, Splunk); 9.0 (CVE-2026-76284); most others 4.1 to 7.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (CVE-2026-76268) - Exploited in Australia?
- unknown
- Patch to
- Upgrade Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15 or later, Splunk Secure Gateway to 3.10.11, 3.9.25 or 3.8.72, and Splunk MCP Server to 1.2.1. Several CVEs need extra steps after upgrading; for example, set scripted_lookup_raw_write_enforcement = block under [lookup] in limits.conf for CVE-2026-76264. If you cannot upgrade a 10.4 or 10.2 search head cluster straight away and do not use Edge Processor, OpAmp or SPL2 data pipelines, Splunk's workaround for CVE-2026-76268 is to turn off the PostgreSQL sidecar (disabled = true in the [postgres] stanza of server.conf) and restart. Limit network access to cluster-internal ports, and use the tar file rather than a Linux package for upgrades until patched (CVE-2026-76266).
Primary: Splunk — SVD-2026-1001: Security Vulnerabilities in Splunk Enterprise, September/October 2026 (7 Oct 2026) · Vendor: Splunk — SVD-2026-1002: Security Hardening in Splunk Enterprise, September/October 2026 (7 Oct 2026) · CVE: CVE-2026-76268, CVE-2026-76266, CVE-2026-76269, CVE-2026-76270, CVE-2026-76274, CVE-2026-76265, CVE-2026-76281, CVE-2026-76284, CVE-2026-76286 · Splunk — SVD-2026-1004: Security Vulnerability in Splunk MCP Server, CVE-2026-76286 (7 Oct 2026)
