Authentication Bypass by Spoofing in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76356
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to authentication bypass through IP address spoofing in the Automation Broker notification endpoint when handling a crafted request with a spoofed client-supplied source IP address header. A remote attacker can send a crafted request to execute arbitrary code.