
CVE-2026-76356: IP-spoofing auth bypass in the Automation Broker of Splunk SOAR, the SOAR platform used to automate incident response. The broker trusts a client-supplied source IP header as proof of a local request. Spoof it, reach privileged functionality, no authentication needed, and execute arbitrary code on the host. Patched in v8.6.0. Found by a CyStack researcher. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #Splunk #SOAR #RCE #EnterpriseSecurity #InfoSec
