Splunk fixes Enterprise flaw that could permit commands without login

First reported by Cyber Security News at · Updated · 2 sources

According to Cyber Security News, CVE-2026-76268 affects the Patroni REST API on Splunk Enterprise search head cluster members and could allow attackers to execute operating system commands without authentication. The outlet reports that the vulnerability has a CVSS v3.1 severity score of 9.8 and was disclosed on October 7, 2026.

Covered by 2 publishers within 6 hours of the first report.

Reporting2

SecurityWeek SonicWall and Splunk Patch Critical Vulnerabilities · Ionut Arghire