Splunk Enterprise: 22 Vulnerabilities Disclosed, Including Critical RCE and Privilege Escalation
Key findings • Splunk Enterprise: 22 vulnerabilities disclosed on October 7, 2026, ranging from Medium to Critical severity. • Vulnerabilities include RCE via Patroni API (CVE-2026-76268) and…
Key findings
- Splunk Enterprise: 22 vulnerabilities disclosed on October 7, 2026, ranging from Medium to Critical severity.
- Vulnerabilities include RCE via Patroni API (CVE-2026-76268) and privilege escalation during Linux package upgrades (CVE-2026-76266).
- Multiple CVEs detail unauthorized access to sensitive data and system functions by low-privileged users.
- Patched versions include Splunk Enterprise 10.4.3, 10.2.7, 10.0.10, and 9.4.15.
- Issues span improper access control, data manipulation, and coding standard adherence across the platform.
On October 7, 2026, Splunk disclosed a significant batch of 22 vulnerabilities affecting Splunk Enterprise. These vulnerabilities, ranging in severity from Medium to Critical, were all identified internally by Splunk and addressed in coordinated updates. The disclosures highlight potential weaknesses across various components of the Splunk platform, impacting authentication, data handling, and system command execution.
Several vulnerabilities revolve around improper access control and data exposure. CVE-2026-76281, CVE-2026-76275, and CVE-2026-76269 detail how authenticated users without administrative privileges could access sensitive search job information and metadata belonging to other users. Similarly, CVE-2026-76276 and CVE-2026-76274 indicate that low-privileged users could retrieve source code for Splunk Observability Cloud apps or redirect outbound requests to attacker-controlled hosts. CVE-2026-76280 and CVE-2026-76265 point to issues within Splunk Secure Gateway, where unauthorized users could modify alert data or access privileged functionality.
Other vulnerabilities focus on the potential for data manipulation and system compromise. CVE-2026-76279 and CVE-2026-76273 describe how users with specific capabilities could write events to internal indexes or inject content into system-level messages. CVE-2026-76270 involves an SQL injection vulnerability in SPL2 module filtering, allowing access to private module definitions. A particularly severe vulnerability, CVE-2026-76268, allows an unauthenticated user with network access to the Patroni REST API to execute arbitrary OS commands with root privileges on search head cluster members. Additionally, CVE-2026-76266 poses a risk on Linux systems, where a local user could execute OS commands with root privileges during a package upgrade.
The batch also includes vulnerabilities related to coding standards and resource management. CVE-2026-76285, CVE-2026-76284, CVE-2026-76283, CVE-2026-76282, and CVE-2026-76278 point to issues such as improper adherence to coding standards, neutralization failures, protection mechanism failures, improper control of resources, and unauthorized access to permission grants for SPL2 modules. CVE-2026-76277 highlights a flaw in username validation that could allow trailing periods, and CVE-2026-76264 involves the creation or editing of scripted lookup definitions through raw configuration endpoints.
Splunk addressed these vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. Specific versions of Splunk Secure Gateway were also updated, including versions below 3.10.11, 3.9.25, and 3.8.72. Users are strongly advised to update to the patched versions to mitigate these risks. The coordinated disclosure of these numerous vulnerabilities underscores the importance of regular patching and security reviews for Splunk deployments.
This extensive set of disclosures serves as a critical reminder for organizations using Splunk Enterprise to promptly apply security updates. The range of vulnerabilities, from information disclosure to remote code execution, necessitates a thorough review of affected systems and a swift patching strategy. Staying current with Splunk's security advisories is paramount to maintaining a secure operating environment.