CVE-2026-76268: Missing Authentication for Critical Function in the Patroni REST API in Splunk Enterprise
In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation.
Splunk Enterprise versions 10.0.x and 9.4.x are not affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.4.3 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.2.7 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 10.0.10 - Upgrade
Upgrade
Splunk Enterpriseto a version that resolves this vulnerability.Fixed in 9.4.15
Event History
Frequently Asked Questions
Which deployments are affected?
Splunk Enterprise versions below 10.4.3 and 10.2.7 are affected when the Patroni REST API is reachable on a search head cluster member. Splunk Enterprise 10.0.x and 9.4.x are not affected.
What does an attacker need to exploit this issue?
An attacker needs network access to the Patroni REST API on a search head cluster member. No authentication or user interaction is required.
What could successful exploitation allow?
An unauthenticated attacker could execute attacker-controlled operating-system commands through critical configuration operations exposed by the API.