Server-Side Request Forgery (SSRF) in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76361

 

Server-Side Request Forgery (SSRF) in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76361

Published: August 20, 2026


Vulnerability identifier: #VU144492
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76361
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to server-side request forgery in the connectivity check REST API when processing a user-supplied destination. A remote privileged user can cause the server to initiate outbound network connections to arbitrary destinations to disclose sensitive information.

The issue can be used to determine whether internal hosts and ports are reachable.


Affected software

Splunk Security Orchestration, Automation and Response (SOAR)

How to mitigate CVE-2026-76361

Install security update from vendor's website.

Splunk Security Orchestration, Automation and Response (SOAR) - update to 8.6.0

External References

Related Security Bulletins