Splunk patches unauthenticated RCE in its own SIEM
Splunk released fixes for CVE-2026-76268 (CVSS 9.1), an unauthenticated RCE in Splunk Enterprise via the Patroni REST API on search head cluster members. Versions 10.4.0–10.4.2 and 10.2.0–10.2.6 are affected; fixes ship in 10.4.3, 10.2.7, 10.0.10 and 9.4.15.
- CVE-2026-76268: CVSS 9.1, unauthenticated RCE via Patroni REST API
- Affected: 10.4.0–10.4.2 and 10.2.0–10.2.6; 10.0.x and 9.4.x unaffected
- 17 CVEs total across four branches, including SQL injection and SSRF in MCP Server
- Workaround: set disabled = true in the [postgres] stanza of server.conf
Read next
Security