CVE-2026-76356

HIGH CVSS 3.1: 8.1 EPSS 0.36%
Updated Aug 27, 2026
Splunk
Parameter Value
CVSS 8.1 (HIGH)
Affected Versions before 8.6.0
Fixed In 8.6.0
Type CWE-290
Vendor Splunk
Public PoC No

In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation Broker trusts a client-supplied source IP address header as proof that the request originates from the local system. Successful exploitation can expose all relevant data, affect system integrity, and disrupt service availability.

For more information see About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Splunk Soar
cpe:2.3:a:splunk:soar:*:*:*:*:cloud:*:*:*
8.6.0
Splunk Soar
cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:*
8.6.0