SPLUNK has released advisories patching 22 vulnerabilities across four Splunk Enterprise branches, including a high‑severity, unauthenticated remote command execution flaw in the Patroni REST API. The most severe, CVE-2026-76268, carries a CVSS v3 score of 9.8 and would allow an attacker with network access to execute operating‑system commands on a search head cluster member. Splunk notes that the Patroni bug is addressed only in the 10.4 and 10.2 lines; versions 10.0.x and 9.4.x are not affected. No exploitation in the wild is confirmed in the article.
The four affected branches are 10.4.0–10.4.2 (fixed in 10.4.3), 10.2.0–10.2.6 (fixed in 10.2.7), 10.0.0–10.0.9 (fixed in 10.0.10), and 9.4.0–9.4.14 (fixed in 9.4.15). In addition to the Patroni issue, 17 other flaws are addressed in SVD-2026-1001, while SVD-2026-1002 provides a hardening release grouping five CVEs by weakness class. Among the notable fixed CVEs are CVE-2026-76266 (local privilege escalation during Linux package upgrades) and several REST API and access control vulnerabilities.
Splunk lists four CVEs requiring additional steps beyond a simple upgrade: CVE-2026-76264, 76265, 76272 and 76280. Administrators are advised to apply the latest updates and, if patching is not immediate, to disable the PostgreSQL sidecar where feasible and restrict network access to search head cluster members until patches are applied. The article presents the advisories as not exploited and provides no public PoC.