SB2026082084 - Multiple vulnerabilities in Splunk SOAR



SB2026082084 - Multiple vulnerabilities in Splunk SOAR

Published: August 20, 2026

Security Bulletin ID SB2026082084
CSH Severity
High
Patch available
YES
Number of vulnerabilities 15
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

High 13% Medium 7% Low 80%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 15 vulnerabilities.


1) Improper Neutralization of Special Elements in Output Used by a Downstream Component (CVE-ID: CVE-2026-76365)

CWE-ID: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to run arbitrary SQL statements.

The vulnerability exists due to SQL injection in custom list retrieval in a playbook when building the custom list database lookup with a supplied list name instead of a bound SQL value. A remote privileged user can supply a crafted list name to run arbitrary SQL statements.

This can create, read, update, or delete all relevant data stored in the database.


2) Authentication Bypass by Spoofing (CVE-ID: CVE-2026-76356)

CWE-ID: CWE-290 - Authentication Bypass by Spoofing

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to authentication bypass through IP address spoofing in the Automation Broker notification endpoint when handling a crafted request with a spoofed client-supplied source IP address header. A remote attacker can send a crafted request to execute arbitrary code.


3) Path traversal (CVE-ID: CVE-2026-76357)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to path traversal in the REST API when processing a crafted file path. A remote user can submit a crafted file path to execute arbitrary code.

The affected request does not require an assigned role.


4) Path traversal (CVE-ID: CVE-2026-76358)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify files outside the intended temporary directory.

The vulnerability exists due to path traversal in the app installation archive extraction routine when extracting a crafted tar archive. A remote privileged user can supply a crafted archive to modify files outside the intended temporary directory.


5) Path traversal (CVE-ID: CVE-2026-76359)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify files outside the intended installation directory.

The vulnerability exists due to path traversal in the Universal Forwarder installer archive extraction workflow when extracting a crafted archive. A remote privileged user can supply a crafted archive to modify files outside the intended installation directory.


6) Missing Authorization (CVE-ID: CVE-2026-76360)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the /rest/health endpoint when handling requests for system health and cluster state. A remote user can query the endpoint to disclose sensitive information.

The exposed data includes system and cluster telemetry.


7) Server-Side Request Forgery (SSRF) (CVE-ID: CVE-2026-76361)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to server-side request forgery in the connectivity check REST API when processing a user-supplied destination. A remote privileged user can cause the server to initiate outbound network connections to arbitrary destinations to disclose sensitive information.

The issue can be used to determine whether internal hosts and ports are reachable.


8) Improper Neutralization of Special Elements in Data Query Logic (CVE-ID: CVE-2026-76363)

CWE-ID: CWE-943 - Improper Neutralization of Special Elements in Data Query Logic

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to run arbitrary SQL statements.

The vulnerability exists due to SQL injection in the playbook automation data APIs when incorporating user-supplied input into database queries. A remote privileged user can supply crafted input to run arbitrary SQL statements.

This can create, read, update, or delete all data in the database.


9) SQL injection (CVE-ID: CVE-2026-76364)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to run arbitrary SQL statements.

The vulnerability exists due to SQL injection in custom function results processing when building a database lookup with a supplied name instead of a bound SQL value. A remote privileged user can supply a crafted name to run arbitrary SQL statements.


10) Improper Certificate Validation (CVE-ID: CVE-2026-76362)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access or modify sensitive data exchanged through the credential manager.

The vulnerability exists due to improper certificate validation in the CyberArk REST client when communicating with a configured CyberArk REST server. A remote attacker can intercept or alter network traffic to access or modify sensitive data exchanged through the credential manager.

Exploitation requires network-path interception capability between Splunk SOAR and the configured CyberArk REST server.


11) Information disclosure (CVE-ID: CVE-2026-76366)

CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to information disclosure in REST API filtering on playbook runs when matching filter values in hidden response fields. A remote user can use crafted REST API filters to disclose sensitive information.

The issue can expose session tokens.


12) Cross-site scripting (CVE-ID: CVE-2026-76367)

CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVSSv4: 2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]


The vulnerability allows a remote user to execute arbitrary script in another user's browser.

The vulnerability exists due to stored cross-site scripting in notes when changing the note format and rendering existing note content as HTML without sanitization. A remote privileged user can store crafted JavaScript in a note to execute arbitrary script in another user's browser.

User interaction is required to open the note, and exploitation requires tricking the victim into initiating a request within their browser.


13) Missing Authorization (CVE-ID: CVE-2026-76368)

CWE-ID: CWE-862 - Missing Authorization

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in Playbook History when returning playbook revision metadata without checking repository permissions. A remote privileged user can view unauthorized playbook repository metadata to disclose sensitive information.


14) Path traversal (CVE-ID: CVE-2026-76369)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to modify files outside the intended Automation Broker log directory.

The vulnerability exists due to path traversal in Automation Broker log uploads when processing a crafted filename. A remote privileged user can supply a crafted filename to modify files outside the intended Automation Broker log directory.


15) Incorrect authorization (CVE-ID: CVE-2026-76370)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper authorization in the REST API when returning tenant information without enforcing role-based tenant restrictions. A remote user can query the REST API to disclose sensitive information.

Only deployments with multi-tenancy turned on are vulnerable.


Remediation

Install update from vendor's website.