Improper Neutralization of Special Elements in Data Query Logic in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76363

 

Improper Neutralization of Special Elements in Data Query Logic in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76363

Published: August 20, 2026


Vulnerability identifier: #VU144494
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76363
CWE-ID: CWE-943
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to run arbitrary SQL statements.

The vulnerability exists due to SQL injection in the playbook automation data APIs when incorporating user-supplied input into database queries. A remote privileged user can supply crafted input to run arbitrary SQL statements.

This can create, read, update, or delete all data in the database.


Affected software

Splunk Security Orchestration, Automation and Response (SOAR)

How to mitigate CVE-2026-76363

Install security update from vendor's website.

Splunk Security Orchestration, Automation and Response (SOAR) - update to 8.6.0

External References

Related Security Bulletins