Server-Side Request Forgery (SSRF) in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76361
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to server-side request forgery in the connectivity check REST API when processing a user-supplied destination. A remote privileged user can cause the server to initiate outbound network connections to arbitrary destinations to disclose sensitive information.
The issue can be used to determine whether internal hosts and ports are reachable.