Splunk search head clusters can be taken over without a login — upgrade to this week’s release or switch off the sidecar

By George Bailey   Published: 10/09/26   4 min read

Your SIEM is the system you trust to tell you when something is wrong, so it’s easy to forget it needs patching too. Splunk’s October 7 release fixes a critical bug that lets anyone who can reach one internal service on a search head cluster member run commands on it, no login required.

Nobody has reported exploitation. That makes this a scheduled weekend upgrade, as long as the right people know it exists.

The box that watches everything else shouldn’t be the one with the open side door.

What happened

Splunk published SVD-2026-1001 on October 7, fixing 17 vulnerabilities in Splunk Enterprise. The headline is CVE-2026-76268 (CVSS 9.8). The Patroni REST API, part of the PostgreSQL sidecar on search head cluster members, doesn’t require authentication for critical configuration operations. An unauthenticated attacker with network access to it can execute operating-system commands. It affects 10.4 below 10.4.3 and 10.2 below 10.2.7. Versions 10.0 and 9.4 are not affected by this one.

A separate hardening release, SVD-2026-1002, adds more critical- and high-rated fixes across all supported lines. The same upgrade covers both: 10.4.3, 10.2.7, 10.0.10 or 9.4.15.

Why it matters

Splunk holds your logs, your saved searches and, often, credentials for everything it collects from. An attacker on a search head can blind your detection or read what you’ve collected. The lower-rated bugs in the same release include search-job data leaking to other users and a Linux package-upgrade privilege escalation, which matters on shared admin hosts.

What to do first

Forward this

For whoever runs our Splunk: Splunk shipped fixes on October 7, including a critical one (no login needed) on 10.2 and 10.4 search head clusters. It isn’t exploited yet. Can we get to 10.4.3 / 10.2.7 / 10.0.10 / 9.4.15 this weekend, or apply the documented sidecar workaround until we can?

Details

Hunt / verify

Slack paste: Splunk SVD-2026-1001 (Oct 7): unauthenticated command execution via the Patroni REST API on 10.2/10.4 search head cluster members (9.8). Not exploited. Upgrade to 10.4.3 / 10.2.7 / 10.0.10 / 9.4.15 + Secure Gateway 3.10.11/3.9.25/3.8.72; workaround: [postgres] disabled = true if no Edge Processor/OpAmp/SPL2 pipelines.

Sources

George Bailey

George Bailey is the byline of the CyberExperts editorial desk, the team behind the CyberExperts Daily Brief. The desk covers vulnerabilities, breaches and security news from vendor advisories, CISA alerts and other primary sources, and links those sources in every story. Questions or corrections: [email protected].