Splunk · Splunk Soar · CVE-2026-76356
**Name of the Vulnerable Software and Affected Versions**
Splunk SOAR versions prior to 8.6.0
**Description**
An unauthenticated user can execute arbitrary code on the host by spoofing the source IP address in a crafted request to an Automation Broker notification endpoint. This occurs because the Automation Broker trusts a client-supplied source IP address header to verify that the request originates from the local system. Successful exploitation may lead to data exposure, compromised system integrity, and service disruption.
**Recommendations**
Update to version 8.6.0 or later.