Threat reportVulnerabilityTL-2026-3110

Splunk Enterprise and Secure Gateway: 22 vulnerabilities patched (SVD-2026-1001/1002), including critical CVE-2026-76268 (Patroni REST API missing authentication, CVSS 9.8) and CVE-2026-76281 (listed 9.8 in advisory)

criticalPATCHED

Splunk Enterprise and Secure Gateway (TL-2026-3110), also tracked as SVD-2026-1001, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-10-09. It has no confirmed attribution, affects Splunk Splunk Enterprise, references 22 CVEs (CVE-2026-76268, CVE-2026-76281, CVE-2026-76284), maps to 6 MITRE ATT&CK techniques (T1059, T1078, T1190), and is covered by 9 detection rules and 8 indicators of compromise.

CVSS
9.8/10Critical
CVEs
22Referenced vulnerabilities
Techniques
6MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
8Indicators of compromise

Key facts for TL-2026-3110

Threat ID
TL-2026-3110
Also known as
SVD-2026-1001, SVD-2026-1002
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, finance, government administration, health, telecoms
Target regions
Global
Detection rules
9
Indicators of compromise
8

Malware and tooling in Splunk Enterprise and Secure Gateway

Malware and tooling: Splunk O11y apps (Discover O11y), Splunk Secure Gateway

How Splunk Enterprise and Secure Gateway works

Splunk patched 22 vulnerabilities (CVE-2026-76264 through CVE-2026-76285) in Splunk Enterprise and Splunk Secure Gateway on 2026-10-07. CVE-2026-76268 is missing authentication (CWE-306) in the Patroni REST API on search head cluster members, allowing an unauthenticated network attacker to execute operating-system commands (CVSS 9.8). No source states active exploitation or a public PoC.

Splunk published two advisories on 2026-10-07. SVD-2026-1001 (Security Vulnerabilities in Splunk Enterprise - September/October 2026) covers 17 CVEs, CVE-2026-76264 to CVE-2026-76280. SVD-2026-1002 (Security Hardening in Splunk Enterprise) covers five internally identified issues, CVE-2026-76281 to CVE-2026-76285.

The most severe issue is CVE-2026-76268 (CWE-306, CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated user with network access to the Patroni REST API on a Splunk Enterprise search head cluster member can execute attacker-controlled operating-system commands, because critical configuration operations do not require authentication. The CVE record lists only Splunk Enterprise 10.4.x before 10.4.3 and 10.2.x before 10.2.7 as affected; 10.0.x and 9.4.x are stated as unaffected. The advisory text for SVD-2026-1001 is worded inconsistently on this point, so the CVE record is treated as authoritative. The documented workaround is to disable the PostgreSQL sidecar by setting disabled = true in server.conf.

SVD-2026-1002 lists CVE-2026-76281 (CWE-284) at CVSS 9.8, CVE-2026-76284 (CWE-707) at 9.0, CVE-2026-76282 (CWE-664) at 8.8, CVE-2026-76283 (CWE-693) at 7.6 and CVE-2026-76285 (CWE-710) at 4.4. Source discrepancy: the CVE record for CVE-2026-76281 (updated 2026-10-08) gives CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) rather than 9.8, so the 9.8 rating for this CVE should be treated as unconfirmed. The advisory gives no description, vector or workaround for these five.

Other notable SVD-2026-1001 issues: CVE-2026-76266 (CWE-269, CVSS 7.7) is a local privilege escalation through malicious content during Linux package upgrades, mitigated by using the tar installation instead of packages. CVE-2026-76270 (CWE-89, CVSS 6.5) is SQL injection in the SPL2 module catalog (user input not parameterized), where an authenticated user with the list_spl2_modules capability can read private SPL2 module definitions of other users; only 10.4.x is affected. CVE-2026-76274 (CWE-918, CVSS 6.5) is SSRF through the O11y app REST API. CVE-2026-76269 and CVE-2026-76275 expose search job data. CVE-2026-76265, CVE-2026-76272 and CVE-2026-76280 affect Splunk Secure Gateway (missing access control and KV Store permission assignment). CVE-2026-76271 is a denial of service in the Discover O11y app, CVE-2026-76267 is log injection, CVE-2026-76276 is information disclosure via source maps, and CVE-2026-76264, CVE-2026-76273, CVE-2026-76277, CVE-2026-76278 and CVE-2026-76279 are authorization or input-validation flaws. Workarounds are scripted_lookup_raw_write_enforcement = block in limits.conf for CVE-2026-76264, removing the run_collect capability from non-admin roles for CVE-2026-76279, and disabling Secure Gateway or the O11y apps if unused.

No source reports in-the-wild exploitation, a public PoC, or IOCs. BeaconBeagle correlation was not applicable because there are no network IOCs. IOCs recorded below are defensive artifacts: vulnerable components, version strings and configuration settings useful for exposure assessment.

MITRE ATT&CK techniques used in TL-2026-3110

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Collection

T1213 Data from Information Repositories

Credential Access

T1552 Unsecured Credentials

Impact

T1565.001 Stored Data Manipulation

Affected products and versions in Splunk Enterprise and Secure Gateway

  • Splunk — Splunk Enterprise
    Vulnerable versions: 10.4.0 to 10.4.2; 10.2.0 to 10.2.6; 10.0.0 to 10.0.9; 9.4.0 to 9.4.14
    Fixed in: 10.4.3; 10.2.7; 10.0.10; 9.4.15
  • Splunk — Splunk Secure Gateway
    Vulnerable versions: below 3.10.11; below 3.9.25; below 3.8.72
    Fixed in: 3.10.11; 3.9.25; 3.8.72

Remediation for Splunk Enterprise and Secure Gateway

Patches

  • SVD-2026-1001
  • SVD-2026-1002

Immediate actions

  • Upgrade Splunk Enterprise to 10.4.3, 10.2.7, 10.0.10 or 9.4.15 (or later)
  • Upgrade Splunk Secure Gateway to 3.10.11, 3.9.25 or 3.8.72
  • Restrict network access to Patroni REST API on search head cluster members until patched

Workarounds

  • CVE-2026-76268: set disabled = true for the PostgreSQL sidecar in server.conf
  • CVE-2026-76264: set scripted_lookup_raw_write_enforcement = block in limits.conf
  • CVE-2026-76266: upgrade using the tar file rather than the Linux package manager
  • CVE-2026-76279: remove run_collect capability from non-admin roles

Longer-term hardening

  • Remove the run_collect capability from roles that lack internal-index access
  • Disable Splunk Secure Gateway and O11y-related apps where not required
  • Monitor Splunk management and cluster ports for unauthenticated access

CVEs associated with Splunk Enterprise and Secure Gateway

Weaknesses (CWE) in Splunk Enterprise and Secure Gateway

CWE-306, CWE-284, CWE-269, CWE-89, CWE-918, CWE-863, CWE-639, CWE-862, CWE-285, CWE-732

Timeline of Splunk Enterprise and Secure Gateway

  • CVE-2026-76268, CVE-2026-76281, CVE-2026-76284 and CVE-2026-76270 reserved (per CVE records)
  • Fixed releases available: Enterprise 10.4.3, 10.2.7, 10.0.10, 9.4.15; Secure Gateway 3.10.11, 3.9.25, 3.8.72
  • Splunk publishes SVD-2026-1001 and SVD-2026-1002 covering 22 CVEs in Splunk Enterprise and Secure Gateway
  • CVE-2026-76281 record updated, listing CVSS 5.3 versus 9.8 in the advisory table
  • The Cyber Express reports the 22 patched vulnerabilities and does not state in-the-wild exploitation
  • CVE-2026-76268 record updated with CVSS 9.8 vector and PostgreSQL sidecar workaround

Sources cited for Splunk Enterprise and Secure Gateway

Detection coverage for TL-2026-3110

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3110 across Splunk SPL, Microsoft KQL and Sigma, covering 8 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
8 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats