Your SIEM is the system you trust to tell you when something is wrong, so it’s easy to forget it needs patching too. Splunk’s October 7 release fixes a critical bug that lets anyone who can reach one internal service on a search head cluster member run commands on it, no login required.
Nobody has reported exploitation. That makes this a scheduled weekend upgrade, as long as the right people know it exists.
The box that watches everything else shouldn’t be the one with the open side door.
The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
Splunk published SVD-2026-1001 on October 7, fixing 17 vulnerabilities in Splunk Enterprise. The headline is CVE-2026-76268 (CVSS 9.8). The Patroni REST API, part of the PostgreSQL sidecar on search head cluster members, doesn’t require authentication for critical configuration operations. An unauthenticated attacker with network access to it can execute operating-system commands. It affects 10.4 below 10.4.3 and 10.2 below 10.2.7. Versions 10.0 and 9.4 are not affected by this one.
A separate hardening release, SVD-2026-1002, adds more critical- and high-rated fixes across all supported lines. The same upgrade covers both: 10.4.3, 10.2.7, 10.0.10 or 9.4.15.
Why it matters
Splunk holds your logs, your saved searches and, often, credentials for everything it collects from. An attacker on a search head can blind your detection or read what you’ve collected. The lower-rated bugs in the same release include search-job data leaking to other users and a Linux package-upgrade privilege escalation, which matters on shared admin hosts.
What to do first
- Upgrade Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15 (or later), whichever matches your line.
- If you run 10.2 or 10.4 search head clusters and can’t upgrade this weekend: if you don’t use Edge Processor, OpAmp or SPL2 data pipelines, set
disabled = truein the[postgres]stanza of$SPLUNK_HOME/etc/system/local/server.confand restart. Then make sure the sidecar ports aren’t reachable from user networks. - Upgrade Splunk Secure Gateway to 3.10.11, 3.9.25 or 3.8.72. If nobody uses Splunk Mobile, Spacebridge or Mission Control, consider disabling it.
- On Linux, upgrade with the tar file rather than the RPM/DEB package if anyone other than Splunk admins can act as the Splunk user (CVE-2026-76266).
Forward this
For whoever runs our Splunk: Splunk shipped fixes on October 7, including a critical one (no login needed) on 10.2 and 10.4 search head clusters. It isn’t exploited yet. Can we get to 10.4.3 / 10.2.7 / 10.0.10 / 9.4.15 this weekend, or apply the documented sidecar workaround until we can?
Details
- Advisory: SVD-2026-1001, “Security Vulnerabilities in Splunk Enterprise – September/October 2026,” published October 7, 2026. Highest score 9.8.
- Critical: CVE-2026-76268, missing authentication in the Patroni REST API (CWE-306), search head cluster members on 10.4.0–10.4.2 and 10.2.0–10.2.6.
- Fixed versions: 10.4.3, 10.2.7, 10.0.10, 9.4.15. Splunk Secure Gateway: 3.10.11, 3.9.25, 3.8.72.
- Extra steps after upgrading: CVE-2026-76264 needs
scripted_lookup_raw_write_enforcement = blockunder[lookup]inlimits.conf. CVE-2026-76265, -76272 and -76280 need the Secure Gateway update. - Also published: SVD-2026-1002 (hardening release, all supported lines) and SVD-2026-1004 (Splunk MCP Server, fixed in 1.2.1).
- Exploitation: None reported by Splunk at publication.
Hunt / verify
- From a user-network host, test whether you can reach the PostgreSQL sidecar / Patroni ports on any search head cluster member. You shouldn’t be able to.
- Review OS process trees on search heads for shells or downloaders spawned by sidecar processes since October 7.
- Check
_auditfor unexpected scripted lookup definitions and for search-job access by users who didn’t own the jobs.
Slack paste: Splunk SVD-2026-1001 (Oct 7): unauthenticated command execution via the Patroni REST API on 10.2/10.4 search head cluster members (9.8). Not exploited. Upgrade to 10.4.3 / 10.2.7 / 10.0.10 / 9.4.15 + Secure Gateway 3.10.11/3.9.25/3.8.72; workaround: [postgres] disabled = true if no Edge Processor/OpAmp/SPL2 pipelines.
Sources
- Splunk: SVD-2026-1001 Security Vulnerabilities in Splunk Enterprise
- Splunk: SVD-2026-1002 Splunk Enterprise hardening release
- Splunk: SVD-2026-1004 Splunk MCP Server
- SecurityWeek: SonicWall and Splunk patch critical vulnerabilities
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.