# Splunk Enterprise and Secure Gateway: 22 vulnerabilities patched (SVD-2026-1001/1002), including critical CVE-2026-76268 (Patroni REST API missing authentication, CVSS 9.8) and CVE-2026-76281 (listed 9.8 in advisory)

> Splunk patched 22 vulnerabilities (CVE-2026-76264 through CVE-2026-76285) in Splunk Enterprise and Splunk Secure Gateway on 2026-10-07. CVE-2026-76268 is missing authentication (CWE-306) in the Patroni REST API on search head cluster members, allowing an unauthenticated network attacker to execute operating-system commands (CVSS 9.8). No source states active exploitation or a public PoC.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3110
- **ID:** TL-2026-3110
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 8 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-76268, CVE-2026-76281, CVE-2026-76284, CVE-2026-76282, CVE-2026-76283, CVE-2026-76266, CVE-2026-76265, CVE-2026-76269, CVE-2026-76270, CVE-2026-76274, CVE-2026-76280, CVE-2026-76272, CVE-2026-76275, CVE-2026-76278, CVE-2026-76285, CVE-2026-76277, CVE-2026-76264, CVE-2026-76267, CVE-2026-76271, CVE-2026-76273, CVE-2026-76276, CVE-2026-76279

## Description

Splunk published two advisories on 2026-10-07. SVD-2026-1001 (Security Vulnerabilities in Splunk Enterprise - September/October 2026) covers 17 CVEs, CVE-2026-76264 to CVE-2026-76280. SVD-2026-1002 (Security Hardening in Splunk Enterprise) covers five internally identified issues, CVE-2026-76281 to CVE-2026-76285.

The most severe issue is CVE-2026-76268 (CWE-306, CVSS 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). An unauthenticated user with network access to the Patroni REST API on a Splunk Enterprise search head cluster member can execute attacker-controlled operating-system commands, because critical configuration operations do not require authentication. The CVE record lists only Splunk Enterprise 10.4.x before 10.4.3 and 10.2.x before 10.2.7 as affected; 10.0.x and 9.4.x are stated as unaffected. The advisory text for SVD-2026-1001 is worded inconsistently on this point, so the CVE record is treated as authoritative. The documented workaround is to disable the PostgreSQL sidecar by setting disabled = true in server.conf.

SVD-2026-1002 lists CVE-2026-76281 (CWE-284) at CVSS 9.8, CVE-2026-76284 (CWE-707) at 9.0, CVE-2026-76282 (CWE-664) at 8.8, CVE-2026-76283 (CWE-693) at 7.6 and CVE-2026-76285 (CWE-710) at 4.4. Source discrepancy: the CVE record for CVE-2026-76281 (updated 2026-10-08) gives CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) rather than 9.8, so the 9.8 rating for this CVE should be treated as unconfirmed. The advisory gives no description, vector or workaround for these five.

Other notable SVD-2026-1001 issues: CVE-2026-76266 (CWE-269, CVSS 7.7) is a local privilege escalation through malicious content during Linux package upgrades, mitigated by using the tar installation instead of packages. CVE-2026-76270 (CWE-89, CVSS 6.5) is SQL injection in the SPL2 module catalog (user input not parameterized), where an authenticated user with the list_spl2_modules capability can read private SPL2 module definitions of other users; only 10.4.x is affected. CVE-2026-76274 (CWE-918, CVSS 6.5) is SSRF through the O11y app REST API. CVE-2026-76269 and CVE-2026-76275 expose search job data. CVE-2026-76265, CVE-2026-76272 and CVE-2026-76280 affect Splunk Secure Gateway (missing access control and KV Store permission assignment). CVE-2026-76271 is a denial of service in the Discover O11y app, CVE-2026-76267 is log injection, CVE-2026-76276 is information disclosure via source maps, and CVE-2026-76264, CVE-2026-76273, CVE-2026-76277, CVE-2026-76278 and CVE-2026-76279 are authorization or input-validation flaws. Workarounds are scripted_lookup_raw_write_enforcement = block in limits.conf for CVE-2026-76264, removing the run_collect capability from non-admin roles for CVE-2026-76279, and disabling Secure Gateway or the O11y apps if unused.

No source reports in-the-wild exploitation, a public PoC, or IOCs. BeaconBeagle correlation was not applicable because there are no network IOCs. IOCs recorded below are defensive artifacts: vulnerable components, version strings and configuration settings useful for exposure assessment.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1078 Valid Accounts
- T1213 Data from Information Repositories
- T1552 Unsecured Credentials
- T1565.001 Stored Data Manipulation

## Sources

- [Splunk Advisory SVD-2026-1001: Security Vulnerabilities in Splunk Enterprise](https://advisory.splunk.com/advisories/SVD-2026-1001)
- [Splunk Advisory SVD-2026-1002: Security Hardening in Splunk Enterprise](https://advisory.splunk.com/advisories/SVD-2026-1002)
- [Splunk Patches 22 Vulnerabilities, Including Critical Flaw With CVSS 9.8](https://thecyberexpress.com/splunk-enterprise-critical-flaws/)
- [CVE-2026-76268 CVE record](https://cveawg.mitre.org/api/cve/CVE-2026-76268)
- [CVE-2026-76281 CVE record](https://cveawg.mitre.org/api/cve/CVE-2026-76281)
- [CVE-2026-76284 CVE record](https://cveawg.mitre.org/api/cve/CVE-2026-76284)
- [CVE-2026-76270 CVE record](https://cveawg.mitre.org/api/cve/CVE-2026-76270)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3110
