Splunk · Splunk Soar · CVE-2026-76357
**Name of the Vulnerable Software and Affected Versions**
Splunk SOAR versions prior to 8.6.0
**Description**
An authenticated user without an assigned role can execute arbitrary code by submitting a crafted file path to the Representational State Transfer (REST) API. This occurs because the REST API does not enforce role requirements for requests and fails to restrict user-supplied file paths to the designated temporary directory.
**Recommendations**
Update to version 8.6.0 or later.