Splunk Patches Command Path
Fix available.
Splunk fixed CVE-2026-76268. An unauthenticated user with network access to the Patroni REST API on a search head cluster member can execute operating-system commands.
The CVSS 9.8 interface lacks authentication for critical configuration operations. That makes network reachability, rather than possession of a Splunk account, the first exposure question for defenders.
Match the exact branch
10.4 below 10.4.3 and 10.2 below 10.2.7 are affected; fixes are 10.4.3 and 10.2.7. Versions 10.0.x and 9.4.x are unaffected by this issue.
Those exclusions apply to this vulnerability only. They are not a blanket statement that every release in those branches is clear of the rest of Splunk’s October advisory batch.
Reduce reachability while patching
BlackTree recommends:
- Inventory the cluster. Identify every search head cluster member and the network paths that can reach its Patroni interface.
- Prioritise broad access. Treat internet-facing, cross-zone and widely reachable management paths as the first remediation targets.
- Install the applicable fixed build. Verify the running version after the change instead of relying only on an orchestration report.
- Preserve independent telemetry. Keep host, network and upstream records outside the platform before maintenance, then review unexpected process execution and configuration changes.
Use the fallback carefully
Disable the PostgreSQL sidecar only without Edge Processor, OpAmp or SPL2 pipelines, then restart. Set disabled = true in [postgres].
BlackTree recommends confirming those dependencies with the service owner before applying the fallback. If any named pipeline depends on the sidecar, use the fixed release instead of assuming the configuration change is safe.
What the evidence does not say
Exploitation is not established; no CISA KEV or public exploit is recorded. That absence is not proof of safety, and evidence attached to a different Splunk vulnerability must not be carried into this one.
Teams should therefore separate two questions: whether the interface was reachable, and whether host-level evidence shows unexpected command execution. A clean application alert view cannot answer both on its own.
Sources and publication details
- Splunk SVD-2026-1001. Dated 7 October 2026; clock not shown.
- BlackTree vulnerability record.


