Splunk Enterprise fixes a critical Patroni flaw and 20 other bugs
EditorialBy TrustList Editorial
Four Splunk Secure Gateway fixes ship as an app update as well, and one medium flaw needs a limits.conf change after the upgrade, not just new binaries.
- Cybersecurity
- Vulnerability Management
- Log Management
About Splunk Enterprise fixes a critical Patroni flaw and 20 other bugs
Splunk Enterprise fixes a critical Patroni flaw and 20 other bugs
7 October 2026: Splunk has released Enterprise 10.4.3, 10.2.7, 10.0.10 and 9.4.15 to fix 16 named vulnerabilities and five grouped hardening issues, the worst of them scored CVSS 9.8. The most serious named flaw, CVE-2026-76268, lets an unauthenticated user with network access to the Patroni REST API on a search head cluster member run operating-system commands. Splunk's two advisories do not report any exploitation.
Splunk says every supported line is affected below the following releases:
- 10.4.0 to 10.4.2: upgrade to 10.4.3
- 10.2.0 to 10.2.6: upgrade to 10.2.7
- 10.0.0 to 10.0.9: upgrade to 10.0.10
- 9.4.0 to 9.4.14: upgrade to 9.4.15
CVE-2026-76268 reaches only 10.4.x and 10.2.x, because Splunk says 10.0.x and 9.4.x are not affected. The flaw sits in the PostgreSQL sidecar. Customers who do not use Edge Processor, OpAmp or SPL2 data pipelines can set disabled = true in the [postgres] stanza of server.conf and restart as a stopgap.
SVD-2026-1001 lists 16 CVEs. Besides the Patroni flaw, CVE-2026-76266 is a high-severity (7.7) local privilege escalation during Linux package upgrades, which Splunk says can be avoided by upgrading from a tar file instead of the Linux package. The rest are rated medium, from 4.1 to 6.5, and cover REST API authorization gaps, an SQL injection in the SPL2 Module Catalog and a server-side request forgery in the Splunk Observability Cloud app.
Four of the CVEs need more than the version upgrade. CVE-2026-76264 requires setting scripted_lookup_raw_write_enforcement = block in limits.conf under [lookup] after upgrading. Three affect the Splunk Secure Gateway app, which has its own fixed releases: 3.10.11, 3.9.25 and 3.8.72. Where an upgrade is not possible, Splunk suggests turning off or removing the app, noting that Splunk Mobile, Spacebridge and Mission Control depend on it.
SVD-2026-1002 covers internally found issues grouped by weakness type, with one CVE per group. CVE-2026-76281 is scored 9.8 for improper access control and CVE-2026-76284 is scored 9.0 for improper neutralization. The advisory gives no further detail on either, and the other three groups range from 4.4 to 8.8.
Search head cluster operators should check first whether the Patroni interface is reachable from networks beyond the cluster itself.
Company profile on TrustList: Splunk
Related on TrustList:
Sources
- Splunk: SVD-2026-1001 Security Vulnerabilities in Splunk Enterprise, 7 October 2026
- Splunk: SVD-2026-1002 Security Hardening in Splunk Enterprise, 7 October 2026
- ACN (Italy): Splunk Enterprise vulnerabilities alert, 8 October 2026
Categories & features
- Cybersecurity
- Vulnerability Management
- Log Management
TrustList Weekly
The week in software and IT, in one email
The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More CybersecurityThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.