Skip to content
TrustList
News

Splunk Enterprise fixes a critical Patroni flaw and 20 other bugs

Editorial

By TrustList Editorial

Four Splunk Secure Gateway fixes ship as an app update as well, and one medium flaw needs a limits.conf change after the upgrade, not just new binaries.

About Splunk Enterprise fixes a critical Patroni flaw and 20 other bugs

Splunk Enterprise fixes a critical Patroni flaw and 20 other bugs

7 October 2026: Splunk has released Enterprise 10.4.3, 10.2.7, 10.0.10 and 9.4.15 to fix 16 named vulnerabilities and five grouped hardening issues, the worst of them scored CVSS 9.8. The most serious named flaw, CVE-2026-76268, lets an unauthenticated user with network access to the Patroni REST API on a search head cluster member run operating-system commands. Splunk's two advisories do not report any exploitation.

Splunk says every supported line is affected below the following releases:

  • 10.4.0 to 10.4.2: upgrade to 10.4.3
  • 10.2.0 to 10.2.6: upgrade to 10.2.7
  • 10.0.0 to 10.0.9: upgrade to 10.0.10
  • 9.4.0 to 9.4.14: upgrade to 9.4.15

CVE-2026-76268 reaches only 10.4.x and 10.2.x, because Splunk says 10.0.x and 9.4.x are not affected. The flaw sits in the PostgreSQL sidecar. Customers who do not use Edge Processor, OpAmp or SPL2 data pipelines can set disabled = true in the [postgres] stanza of server.conf and restart as a stopgap.

SVD-2026-1001 lists 16 CVEs. Besides the Patroni flaw, CVE-2026-76266 is a high-severity (7.7) local privilege escalation during Linux package upgrades, which Splunk says can be avoided by upgrading from a tar file instead of the Linux package. The rest are rated medium, from 4.1 to 6.5, and cover REST API authorization gaps, an SQL injection in the SPL2 Module Catalog and a server-side request forgery in the Splunk Observability Cloud app.

Four of the CVEs need more than the version upgrade. CVE-2026-76264 requires setting scripted_lookup_raw_write_enforcement = block in limits.conf under [lookup] after upgrading. Three affect the Splunk Secure Gateway app, which has its own fixed releases: 3.10.11, 3.9.25 and 3.8.72. Where an upgrade is not possible, Splunk suggests turning off or removing the app, noting that Splunk Mobile, Spacebridge and Mission Control depend on it.

SVD-2026-1002 covers internally found issues grouped by weakness type, with one CVE per group. CVE-2026-76281 is scored 9.8 for improper access control and CVE-2026-76284 is scored 9.0 for improper neutralization. The advisory gives no further detail on either, and the other three groups range from 4.4 to 8.8.

Search head cluster operators should check first whether the Patroni interface is reachable from networks beyond the cluster itself.

Company profile on TrustList: Splunk

Related on TrustList:

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy