CVE-2026-76268
Splunk Enterprise Patroni REST API missing authentication allows unauthenticated command execution (CVE-2026-76268)
Splunk Enterprise 10.4 before 10.4.3 and 10.2 before 10.2.7 exposes the Patroni REST API without authentication on search head cluster members. An unauthenticated attacker with network access can execute operating-system commands. Upgrade to Splunk Enterprise 10.4.3 or 10.2.7.
What happened
The Patroni REST API on Splunk Enterprise search head cluster members is meant for critical configuration operations, but in affected releases it does not require authentication (CWE-306). An unauthenticated attacker with network access to that API can submit requests that execute operating-system commands on the host. The CVSS v3.1 score is 9.8 (critical): network reachable, low attack complexity, no privileges or user interaction, and high impact on confidentiality, integrity and availability.
No active exploitation is reported in the CVE record, and no CISA KEV entry is listed for this CVE. The risk is exposure-driven: if the Patroni REST API is reachable from an untrusted network, an attacker needs no credentials to act.
Who is affected
Splunk Enterprise 10.4 to before 10.4.3 and 10.2 to before 10.2.7 are affected. Splunk Enterprise 10.0.x and 9.4.x are not affected. The vulnerable component is the Patroni REST API on search head cluster members, so organisations running search head clusters in those release branches should treat this as urgent. Deployments that do not use search head clustering or do not expose the Patroni REST API still need to verify they are outside the affected versions before deprioritising.
What to do now
- Upgrade affected search head cluster members to Splunk Enterprise 10.4.3 if on 10.4, or 10.2.7 if on 10.2. These are the fixed releases listed in the CVE record.
- Until patching is complete, restrict network access to the Patroni REST API to trusted administrative systems only. This is containment, not a substitute for the upgrade.
- Confirm your release: 10.0.x and 9.4.x are stated as not affected.
How to detect it
Look first for unintended exposure: determine whether the Patroni REST API is reachable from untrusted networks. On affected search head cluster members, review for unexpected operating-system commands or processes, particularly any that coincide with API requests. The CVE record does not list specific indicators of compromise.
Beyond the patch
This flaw starts with an unauthenticated network interface on a search head cluster. Virtual CISO Services can map and prioritise exposures such as an openly reachable Patroni REST API before they become incidents. The missing authentication and command execution are exactly the kind of issue that Implementation & Assessment Services penetration testing and hardening reviews are designed to find.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| Splunk Enterprise | 10.4 – < 10.4.3 10.2 – < 10.2.7 | 10.4.3 10.2.7 |