Splunk fixes Enterprise flaw that could permit commands without login
According to Cyber Security News, CVE-2026-76268 affects the Patroni REST API on Splunk Enterprise search head cluster members and could allow attackers to execute operating system commands without authentication. The outlet reports that the vulnerability has a CVSS v3.1 severity score of 9.8 and was disclosed on October 7, 2026.
Covered by 2 publishers within 6 hours of the first report.
Reporting2
Cyber Security News Splunk Patches Critical 9.8 Flaw Allowing Unauthenticated Remote Command Execution · Abinaya
SecurityWeek SonicWall and Splunk Patch Critical Vulnerabilities · Ionut Arghire