Splunk Enterprise <10.4.3/10.2.7: Unauth OS Cmd Exec via Patroni REST API
CVE-2026-76268 Published on October 7, 2026
Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation.
Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Weakness Type
Missing Authentication for Critical Function
The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Products Associated with CVE-2026-76268
Want to know whenever a new CVE is published for Splunk? stack.watch will email you.
Affected Versions
Splunk Enterprise:- Version 10.4 and below 10.4.3 is affected.
- Version 10.2 and below 10.2.7 is affected.