Known vulnerabilities in Splunk Security Orchestration, Automation and Response (SOAR)

Software CPE: cpe:2.3:a:splunk:soar:*:*:*:*:*:*:*:*
Total vulnerabilities: 32
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Splunk Security Orchestration, Automation and Response (SOAR) Splunk Security Orchestration, Automation and Response (SOAR) is affected by 32 known vulnerabilities: 5 high, 8 medium, 19 low Critical High Medium Low

Vulnerabilities (32)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144494 - Improper Neutralization of Special Elements in Data Query Logic
CVE-2026-76363
CWE-943 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144495 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-76364
CWE-89 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144496 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-76365
CWE-74 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144497 - Exposure of sensitive information to an unauthorized actor
CVE-2026-76366
CWE-200 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144498 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-76367
CWE-79 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144499 - Missing Authorization
CVE-2026-76368
CWE-862 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144500 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-76369
CWE-22 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144501 - Incorrect Authorization
CVE-2026-76370
CWE-863 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144487 - Authentication Bypass by Spoofing
CVE-2026-76356
CWE-290 High
No
No
8.6.0 20.08.2026 SB2026082084
#VU144488 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-76357
CWE-22 High
No
No
8.6.0 20.08.2026 SB2026082084
#VU144489 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-76358
CWE-22 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144490 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-76359
CWE-22 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144491 - Missing Authorization
CVE-2026-76360
CWE-862 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144492 - Server-Side Request Forgery (SSRF)
CVE-2026-76361
CWE-918 Low
No
No
8.6.0 20.08.2026 SB2026082084
#VU144493 - Improper Certificate Validation
CVE-2026-76362
CWE-295 Medium
No
No
8.6.0 20.08.2026 SB2026082084
#VU134464 - Improper Output Neutralization for Logs
CVE-2026-20260
CWE-117 Low
No
No
8.5.0 12.06.2026 SB2026061255
#VU114096 - Improper input validation
CVE-2025-8715
CWE-20 Medium
No
No
7.1.0 14.08.2025 SB2025081496
SB2025081898
SB2025082551
and 52 more
#VU114095 - Improper Control of Generation of Code ('Code Injection')
CVE-2025-8714
CWE-94 Low
Available
No
7.1.0 14.08.2025 SB2025081496
SB2025081898
SB2025082551
and 60 more
#VU114094 - Permissions, Privileges, and Access Controls
CVE-2025-8713
CWE-264 Low
No
No
7.1.0 14.08.2025 SB2025081496
SB2025081898
SB2025082551
and 32 more
#VU109846 - Allocation of Resources Without Limits or Throttling
CVE-2025-47287
CWE-770 Medium
No
No
7.1.0 27.05.2025 SB2025052726
SB2025052727
SB2025052728
and 30 more


Showing elements 1 - 20 out of 32