Critical Splunk Enterprise Vulnerability Lets Unauthenticated Attackers Execute OS Commands

Splunk has addressed a critical vulnerability in Splunk Enterprise that allows unauthenticated attackers to execute operating system commands through the Patroni REST API on a search head cluster member. This issue, tracked as CVE-2026-76268, has a CVSS v3.1 score of 9.8 and was disclosed in advisory SVD-2026-1001 on October 7, 2026. Successful exploitation requires network […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: