{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asplunksplunk_enterprise/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-76268"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Splunk Enterprise (\u003c 10.4.3, \u003c 10.2.7)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","rce","splunk"],"_cs_type":"advisory","_cs_vendors":["Splunk"],"content_html":"\u003cp\u003eCVE-2026-76268 is a critical security vulnerability affecting Splunk Enterprise versions prior to 10.4.3 and 10.2.7. The vulnerability exists within the Patroni REST API component, which is used for cluster management. Due to insufficient authentication checks on this interface, an unauthenticated attacker with network access to a search head cluster member can interact with the API to perform critical configuration operations. By manipulating sidecar configuration settings via the exposed REST endpoint, an attacker can trigger the execution of arbitrary commands on the underlying host operating system with the privileges of the Splunk service account. This issue poses a significant risk to the integrity and confidentiality of the Splunk environment. Organizations running affected versions are strongly advised to upgrade to version 10.4.3, 10.2.7, or later to remediate the vulnerability.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify internet-facing or internally accessible Splunk search head cluster members.\u003c/li\u003e\n\u003cli\u003eAttacker probes the network to verify reachability of the Patroni REST API endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker sends an unauthenticated HTTP request to the Patroni REST API to list existing sidecar configurations.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious configuration payload containing arbitrary shell commands.\u003c/li\u003e\n\u003cli\u003eAttacker submits the payload via a PUT or POST request to the API, bypassing the missing authentication gate.\u003c/li\u003e\n\u003cli\u003eSplunk Enterprise processes the malicious configuration update.\u003c/li\u003e\n\u003cli\u003eThe Patroni sidecar mechanism triggers the configured command, resulting in remote code execution on the search head.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to achieve full code execution on Splunk search head cluster members. This impact enables attackers to pivot into the internal network, exfiltrate indexed data, or gain persistence within the security monitoring infrastructure. Given the critical nature of Splunk as a centralized logging and analysis platform, compromise of search heads could lead to the complete subversion of security operations and observability capabilities.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately upgrade Splunk Enterprise to version 10.4.3 or 10.2.7 to address CVE-2026-76268.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Patroni REST API port on search head cluster members to authorized administrative IP ranges using host-based firewalls or network access control lists.\u003c/li\u003e\n\u003cli\u003eMonitor web server and application logs for unauthorized POST or PUT requests to Patroni REST API endpoints originating from non-authorized internal sources.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T22:56:57Z","date_published":"2026-10-07T22:56:57Z","id":"https://feed.craftedsignal.io/briefs/2026-10-splunk-rest-api-rce/","summary":"An authentication bypass vulnerability in the Splunk Enterprise Patroni REST API allows unauthenticated remote attackers to execute arbitrary system commands via configuration manipulation.","title":"Unauthenticated Remote Code Execution in Splunk Enterprise Patroni REST API","url":"https://feed.craftedsignal.io/briefs/2026-10-splunk-rest-api-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:splunk:splunk_enterprise:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}