PT-2026-78783 · Splunk · Splunk Soar

·

CVE-2026-76356

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Splunk SOAR versions prior to 8.6.0
Description An unauthenticated user can execute arbitrary code on the host by spoofing the source IP address in a crafted request to an Automation Broker notification endpoint. This occurs because the Automation Broker trusts a client-supplied source IP address header to verify that the request originates from the local system. Successful exploitation may lead to data exposure, compromised system integrity, and service disruption.
Recommendations Update to version 8.6.0 or later.

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76356

Affected Products

Splunk Soar