Cross-site scripting in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76367
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in another user's browser.
The vulnerability exists due to stored cross-site scripting in notes when changing the note format and rendering existing note content as HTML without sanitization. A remote privileged user can store crafted JavaScript in a note to execute arbitrary script in another user's browser.
User interaction is required to open the note, and exploitation requires tricking the victim into initiating a request within their browser.