Improper Neutralization of Special Elements in Output Used by a Downstream Component in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76365

 

Improper Neutralization of Special Elements in Output Used by a Downstream Component in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76365

Published: August 20, 2026


Vulnerability identifier: #VU144496
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76365
CWE-ID: CWE-74
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to run arbitrary SQL statements.

The vulnerability exists due to SQL injection in custom list retrieval in a playbook when building the custom list database lookup with a supplied list name instead of a bound SQL value. A remote privileged user can supply a crafted list name to run arbitrary SQL statements.

This can create, read, update, or delete all relevant data stored in the database.


Affected software

Splunk Security Orchestration, Automation and Response (SOAR)

How to mitigate CVE-2026-76365

Install security update from vendor's website.

Splunk Security Orchestration, Automation and Response (SOAR) - update to 8.6.0

External References

Related Security Bulletins