Splunk Patches 22 security flaws, Including Critical Flaw With CVSS
What happened
Splunk has patched a large set of Splunk vulnerabilities in Splunk Enterprise, the most severe of which carries a CVSSv3.1 score of 9.8. A security bulletin issued on October 9, 2026, rated the overall risk as medium and warned that a remote attacker could exploit some of the flaws to achieve remote code execution, denial of service, elevation of privilege, security restriction bypass, sensitive information disclosure, and data manipulation.
The fixes are described in two advisories, SVD-2026-1001 and SVD-2026-1002, both published on October 7, 2026, and together they cover 22 CVE identifiers, CVE-2026-76264 through CVE-2026-76285. Splunk Enterprise Versions Affected Branch Affected versions Fixed version 10.4 10.4.0 to 10.4.2 10.4.3 10.2 10.2.0 to 10.2.6 10.2.7 10.0 10.0.0 to 10.0.9 10.0.10 9.4 9.4.0 to 9.4.14 9.4.15 The Critical Patroni Flaw The top-rated issue, CVE-2026-76268 (CWE-306), stems from missing authentication in the Patroni REST API (the interface one piece of software uses to talk to another). Versions 10.0.x and 9.4.x are not affected.
Sources & evidence
- The Cyber Express Reporting source
Splunk Patches 22 Vulnerabilities, Including Critical Flaw With CVSS 9.8 โ
https://thecyberexpress.com/splunk-enterprise-critical-flaws/