CVE-2026-76356(splunk / soar)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation Broker trusts a client-supplied source IP address header as proof that the request originates from the local system. Successful exploitation can expose all relevant data, affect system integrity, and disrupt service availability. For more information see About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • soar

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
soar

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-15: 109-15
Referenced assets1 URL
By indicator
Full discourse1 post
  • CyStack@CyStackSecurity

    CVE-2026-76356: IP-spoofing auth bypass in the Automation Broker of Splunk SOAR, the SOAR platform used to automate incident response. The broker trusts a client-supplied source IP header as proof of a local request. Spoof it, reach privileged functionality, no authentication needed, and execute arbitrary code on the host. Patched in v8.6.0. Found by a CyStack researcher. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #Splunk #SOAR #RCE #EnterpriseSecurity #InfoSec

    0000057
    3.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunksoar---
Appsplunksoar---

Explore more