Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade Splunk Enterprise to versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15, or higher.
Vendor Workaround
Turn off the PostgreSQL sidecar by setting `disabled = true` in the `[postgres]` stanza of `$SPLUNK_HOME/etc/system/local/server.conf` if you do not use Edge Processor, OpAmp, or SPL2 data pipelines. Restart Splunk Enterprise to apply the change. For more information see [Sidecar configuration settings](https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) and [server.conf](https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/configuration-file-reference/10.2.7-configuration-file-reference/server.conf) in the Splunk documentation.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-1001 |
|
Wed, 07 Oct 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation. Splunk Enterprise versions 10.0.x and 9.4.x are not affected. | |
| Title | Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-10-07T20:46:31.281Z
Reserved: 2026-08-19T12:02:03.620Z
Link: CVE-2026-76268
No data.
Status : Received
Published: 2026-10-07T21:17:17.607
Modified: 2026-10-07T21:17:17.607
Link: CVE-2026-76268
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function