Path traversal in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76369
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to modify files outside the intended Automation Broker log directory.
The vulnerability exists due to path traversal in Automation Broker log uploads when processing a crafted filename. A remote privileged user can supply a crafted filename to modify files outside the intended Automation Broker log directory.