Skip to content

CVE-2026-76268

Splunk Enterprise Patroni REST API missing authentication allows unauthenticated command execution (CVE-2026-76268)

Critical 9.8 Vendor: Cisco Published

Splunk Enterprise 10.4 before 10.4.3 and 10.2 before 10.2.7 exposes the Patroni REST API without authentication on search head cluster members. An unauthenticated attacker with network access can execute operating-system commands. Upgrade to Splunk Enterprise 10.4.3 or 10.2.7.

What happened

The Patroni REST API on Splunk Enterprise search head cluster members is meant for critical configuration operations, but in affected releases it does not require authentication (CWE-306). An unauthenticated attacker with network access to that API can submit requests that execute operating-system commands on the host. The CVSS v3.1 score is 9.8 (critical): network reachable, low attack complexity, no privileges or user interaction, and high impact on confidentiality, integrity and availability.

No active exploitation is reported in the CVE record, and no CISA KEV entry is listed for this CVE. The risk is exposure-driven: if the Patroni REST API is reachable from an untrusted network, an attacker needs no credentials to act.

Who is affected

Splunk Enterprise 10.4 to before 10.4.3 and 10.2 to before 10.2.7 are affected. Splunk Enterprise 10.0.x and 9.4.x are not affected. The vulnerable component is the Patroni REST API on search head cluster members, so organisations running search head clusters in those release branches should treat this as urgent. Deployments that do not use search head clustering or do not expose the Patroni REST API still need to verify they are outside the affected versions before deprioritising.

What to do now

  1. Upgrade affected search head cluster members to Splunk Enterprise 10.4.3 if on 10.4, or 10.2.7 if on 10.2. These are the fixed releases listed in the CVE record.
  2. Until patching is complete, restrict network access to the Patroni REST API to trusted administrative systems only. This is containment, not a substitute for the upgrade.
  3. Confirm your release: 10.0.x and 9.4.x are stated as not affected.

How to detect it

Look first for unintended exposure: determine whether the Patroni REST API is reachable from untrusted networks. On affected search head cluster members, review for unexpected operating-system commands or processes, particularly any that coincide with API requests. The CVE record does not list specific indicators of compromise.

Beyond the patch

This flaw starts with an unauthenticated network interface on a search head cluster. Virtual CISO Services can map and prioritise exposures such as an openly reachable Patroni REST API before they become incidents. The missing authentication and command execution are exactly the kind of issue that Implementation & Assessment Services penetration testing and hardening reviews are designed to find.

Affected and fixed versions

ProductAffectedFixed in
Splunk Enterprise10.4 – < 10.4.3
10.2 – < 10.2.7
10.4.3
10.2.7

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.