Threat reportVulnerabilityTL-2026-3110
Splunk Enterprise and Secure Gateway: 22 vulnerabilities patched (SVD-2026-1001/1002), including critical CVE-2026-76268 (Patroni REST API missing authentication, CVSS 9.8) and CVE-2026-76281 (listed 9.8 in advisory)
Splunk Enterprise and Secure Gateway (TL-2026-3110), also tracked as SVD-2026-1001, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-10-09. It has no confirmed attribution, affects Splunk Splunk Enterprise, references 22 CVEs (CVE-2026-76268, CVE-2026-76281, CVE-2026-76284), maps to 6 MITRE ATT&CK techniques (T1059, T1078, T1190), and is covered by 9 detection rules and 8 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 22Referenced vulnerabilities
- Techniques
- 6MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 8Indicators of compromise
Key facts for TL-2026-3110
- Threat ID
- TL-2026-3110
- Also known as
- SVD-2026-1001, SVD-2026-1002
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, finance, government administration, health, telecoms
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 8
Malware and tooling in Splunk Enterprise and Secure Gateway
Malware and tooling: Splunk O11y apps (Discover O11y), Splunk Secure Gateway
How Splunk Enterprise and Secure Gateway works
Splunk patched 22 vulnerabilities (CVE-2026-76264 through CVE-2026-76285) in Splunk Enterprise and Splunk Secure Gateway on 2026-10-07. CVE-2026-76268 is missing authentication (CWE-306) in the Patroni REST API on search head cluster members, allowing an unauthenticated network attacker to execute operating-system commands (CVSS 9.8). No source states active exploitation or a public PoC.
Splunk published two advisories on 2026-10-07. SVD-2026-1001 (Security Vulnerabilities in Splunk Enterprise - September/October 2026) covers 17 CVEs, CVE-2026-76264 to CVE-2026-76280. SVD-2026-1002 (Security Hardening in Splunk Enterprise) covers five internally identified issues, CVE-2026-76281 to CVE-2026-76285.
The most severe issue is CVE-2026-76268 (CWE-306, CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated user with network access to the Patroni REST API on a Splunk Enterprise search head cluster member can execute attacker-controlled operating-system commands, because critical configuration operations do not require authentication. The CVE record lists only Splunk Enterprise 10.4.x before 10.4.3 and 10.2.x before 10.2.7 as affected; 10.0.x and 9.4.x are stated as unaffected. The advisory text for SVD-2026-1001 is worded inconsistently on this point, so the CVE record is treated as authoritative. The documented workaround is to disable the PostgreSQL sidecar by setting disabled = true in server.conf.
SVD-2026-1002 lists CVE-2026-76281 (CWE-284) at CVSS 9.8, CVE-2026-76284 (CWE-707) at 9.0, CVE-2026-76282 (CWE-664) at 8.8, CVE-2026-76283 (CWE-693) at 7.6 and CVE-2026-76285 (CWE-710) at 4.4. Source discrepancy: the CVE record for CVE-2026-76281 (updated 2026-10-08) gives CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) rather than 9.8, so the 9.8 rating for this CVE should be treated as unconfirmed. The advisory gives no description, vector or workaround for these five.
Other notable SVD-2026-1001 issues: CVE-2026-76266 (CWE-269, CVSS 7.7) is a local privilege escalation through malicious content during Linux package upgrades, mitigated by using the tar installation instead of packages. CVE-2026-76270 (CWE-89, CVSS 6.5) is SQL injection in the SPL2 module catalog (user input not parameterized), where an authenticated user with the list_spl2_modules capability can read private SPL2 module definitions of other users; only 10.4.x is affected. CVE-2026-76274 (CWE-918, CVSS 6.5) is SSRF through the O11y app REST API. CVE-2026-76269 and CVE-2026-76275 expose search job data. CVE-2026-76265, CVE-2026-76272 and CVE-2026-76280 affect Splunk Secure Gateway (missing access control and KV Store permission assignment). CVE-2026-76271 is a denial of service in the Discover O11y app, CVE-2026-76267 is log injection, CVE-2026-76276 is information disclosure via source maps, and CVE-2026-76264, CVE-2026-76273, CVE-2026-76277, CVE-2026-76278 and CVE-2026-76279 are authorization or input-validation flaws. Workarounds are scripted_lookup_raw_write_enforcement = block in limits.conf for CVE-2026-76264, removing the run_collect capability from non-admin roles for CVE-2026-76279, and disabling Secure Gateway or the O11y apps if unused.
No source reports in-the-wild exploitation, a public PoC, or IOCs. BeaconBeagle correlation was not applicable because there are no network IOCs. IOCs recorded below are defensive artifacts: vulnerable components, version strings and configuration settings useful for exposure assessment.
MITRE ATT&CK techniques used in TL-2026-3110
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Collection
T1213 Data from Information Repositories
Credential Access
Impact
Affected products and versions in Splunk Enterprise and Secure Gateway
Remediation for Splunk Enterprise and Secure Gateway
Patches
- SVD-2026-1001
- SVD-2026-1002
Immediate actions
- Upgrade Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15 (or later)
- Upgrade Splunk Secure Gateway to 3.10.11, 3.9.25 or 3.8.72
- Restrict network access to Patroni REST API on search head cluster members until patched
Workarounds
- CVE-2026-76268: set disabled = true for the PostgreSQL sidecar in server.conf
- CVE-2026-76264: set scripted_lookup_raw_write_enforcement = block in limits.conf
- CVE-2026-76266: upgrade using the tar file rather than the Linux package manager
- CVE-2026-76279: remove run_collect capability from non-admin roles
Longer-term hardening
- Remove the run_collect capability from roles that lack internal-index access
- Disable Splunk Secure Gateway and O11y-related apps where not required
- Monitor Splunk management and cluster ports for unauthenticated access
CVEs associated with Splunk Enterprise and Secure Gateway
- CVE-2026-76268
- CVE-2026-76281
- CVE-2026-76284
- CVE-2026-76282
- CVE-2026-76283
- CVE-2026-76266
- CVE-2026-76265
- CVE-2026-76269
- CVE-2026-76270
- CVE-2026-76274
- CVE-2026-76280
- CVE-2026-76272
- CVE-2026-76275
- CVE-2026-76278
- CVE-2026-76285
- CVE-2026-76277
- CVE-2026-76264
- CVE-2026-76267
- CVE-2026-76271
- CVE-2026-76273
- CVE-2026-76276
- CVE-2026-76279
Weaknesses (CWE) in Splunk Enterprise and Secure Gateway
CWE-306, CWE-284, CWE-269, CWE-89, CWE-918, CWE-863, CWE-639, CWE-862, CWE-285, CWE-732
Timeline of Splunk Enterprise and Secure Gateway
- CVE-2026-76268, CVE-2026-76281, CVE-2026-76284 and CVE-2026-76270 reserved (per CVE records)
- Fixed releases available: Enterprise 10.4.3, 10.2.7, 10.0.10, 9.4.15; Secure Gateway 3.10.11, 3.9.25, 3.8.72
- Splunk publishes SVD-2026-1001 and SVD-2026-1002 covering 22 CVEs in Splunk Enterprise and Secure Gateway
- CVE-2026-76281 record updated, listing CVSS 5.3 versus 9.8 in the advisory table
- The Cyber Express reports the 22 patched vulnerabilities and does not state in-the-wild exploitation
- CVE-2026-76268 record updated with CVSS 9.8 vector and PostgreSQL sidecar workaround
Sources cited for Splunk Enterprise and Secure Gateway
- Splunk Advisory SVD-2026-1001: Security Vulnerabilities in Splunk Enterprise
- Splunk Advisory SVD-2026-1002: Security Hardening in Splunk Enterprise
- Splunk Patches 22 Vulnerabilities, Including Critical Flaw With CVSS 9.8
- CVE-2026-76268 CVE record
- CVE-2026-76281 CVE record
- CVE-2026-76284 CVE record
- CVE-2026-76270 CVE record
Detection coverage for TL-2026-3110
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3110 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.