Improper Neutralization of Special Elements in Output Used by a Downstream Component in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76365
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to run arbitrary SQL statements.
The vulnerability exists due to SQL injection in custom list retrieval in a playbook when building the custom list database lookup with a supplied list name instead of a bound SQL value. A remote privileged user can supply a crafted list name to run arbitrary SQL statements.
This can create, read, update, or delete all relevant data stored in the database.