Improper Neutralization of Special Elements in Data Query Logic in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76363
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to run arbitrary SQL statements.
The vulnerability exists due to SQL injection in the playbook automation data APIs when incorporating user-supplied input into database queries. A remote privileged user can supply crafted input to run arbitrary SQL statements.
This can create, read, update, or delete all data in the database.