Splunk has patched a large set of Splunk vulnerabilities in Splunk Enterprise, the most severe of which carries a CVSSv3.1 score of 9.8. The fixes are described in two advisories, SVD-2026-1001 and SVD-2026-1002, both published on October 7, 2026, and together they cover 22 CVE identifiers, CVE-2026-76264 through CVE-2026-76285.
A security bulletin issued on October 9, 2026, rated the overall risk as medium and warned that a remote attacker could exploit some of the flaws to achieve remote code execution, denial of service, elevation of privilege, security restriction bypass, sensitive information disclosure, and data manipulation.
Splunk Enterprise Versions Affected
| Branch | Affected versions | Fixed version |
| 10.4 | 10.4.0 to 10.4.2 | 10.4.3 |
| 10.2 | 10.2.0 to 10.2.6 | 10.2.7 |
| 10.0 | 10.0.0 to 10.0.9 | 10.0.10 |
| 9.4 | 9.4.0 to 9.4.14 | 9.4.15 |
The Critical Patroni Flaw
The top-rated issue, CVE-2026-76268 (CWE-306), stems from missing authentication in the Patroni REST API. On a search head cluster member running a version below 10.4.3 or 10.2.7, an unauthenticated attacker with network access to that interface could run operating-system commands, because critical configuration operations require no login. Versions 10.0.x and 9.4.x are not affected.
Organizations that do not use Edge Processor, OpAmp or SPL2 data pipelines can turn off the PostgreSQL sidecar by setting disabled = true in the [postgres] stanza of $SPLUNK_HOME/etc/system/local/server.conf, then restarting.
Privilege Escalation and Secure Gateway Splunk Vulnerabilities
CVE-2026-76266 (7.7, High) lets a local user who can run commands as the Splunk account plant content that a later Linux package upgrade executes as root. Upgrading with a tar file avoids the issue.
Three flaws hit Splunk Secure Gateway: CVE-2026-76265 (6.5) and CVE-2026-76272 (4.3) let non-admin users make it sign attacker-controlled payloads, while CVE-2026-76280 (6.3) allows writes to alert and mobile-device recipient data. They are fixed in Secure Gateway 3.10.11, 3.9.25 and 3.8.72.

Admins who do not use Splunk Mobile, Spacebridge or Mission Control can disable the app instead.
Data Exposure and Input Validation in Splunk Enterprise
Several medium-severity bugs expose other users’ data. CVE-2026-76269 (6.5) and CVE-2026-76275 (4.3) reveal other users’ search jobs, CVE-2026-76270 (6.5) is a SQL injection in the SPL2 module catalog affecting only 10.4.x, and CVE-2026-76278 (4.3) leaks SPL2 module permission grants. CVE-2026-76274 (6.5), an SSRF, can disclose the Observability Cloud API token.
Others include log injection (CVE-2026-76267), a regex-based denial of service (CVE-2026-76271), source code leaking through source maps (CVE-2026-76276), collect command abuse (CVE-2026-76273, CVE-2026-76279), usernames ending in a period (CVE-2026-76277, 4.1) and scripted lookup edits by non-admins (CVE-2026-76264).
Internally Identified Hardening Fixes
Advisory SVD-2026-1002 groups internal findings by weakness class, scoring each CVE by its worst finding: CVE-2026-76281 (CWE-284, 9.8), CVE-2026-76284 (CWE-707, 9.0), CVE-2026-76282 (CWE-664, 8.8), CVE-2026-76283 (CWE-693, 7.6) and CVE-2026-76285 (CWE-710, 4.4).
Fixing the Splunk Vulnerabilities
Splunk advises upgrading Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15, or later. CVE-2026-76264, CVE-2026-76265, CVE-2026-76272 and CVE-2026-76280 need extra steps. For CVE-2026-76264, admins should set scripted_lookup_raw_write_enforcement = block under [lookup] in limits.conf and restart. Where upgrading is not possible, removing run_collect from roles without internal-index access mitigates CVE-2026-76279.
Credited researchers include Gabriel Nitu of Splunk, Jean-Michel Remi Boudreau, Anton (therceman), M Mahdan Argya Syarif, Saidina Hikam, Alex Hordijk and Younes Zendour.

