---
id: CVE-2026-76268
title: >-
  In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user
  with network access to the Patroni Representational State Transfer (REST)
  Application Programming Interface (API) on a search head cluster member could
  execut…
summary: >-
  In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user
  with network access to the Patroni Representational State Transfer (REST)
  Application Programming Interface (API) on a search head cluster member could
  execut…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-306
vendor: Splunk
product: Splunk Enterprise
affected:
  - enterprise >= 10.4 < 10.4.3
  - enterprise >= 10.2 < 10.2.7
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:17:17.607'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76268'
references:
  - url: 'https://advisory.splunk.com/advisories/SVD-2026-1001'
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-07T21:54:15.093Z'
---

## Overview

In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation.

Splunk Enterprise versions 10.0.x and 9.4.x are not affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
