PT-2026-78798 · Splunk · Fireamp

CVE-2026-76371

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions FireAMP versions prior to 2.1.15
Description A user with permissions to edit, create, or run playbooks in Splunk SOAR can execute the add listitem action within a Safe Mode playbook. This is possible because the FireAMP connector action manifest incorrectly classifies the add listitem action as read-only, despite the fact that it updates file lists, potentially leading to unauthorized modifications of those lists.
Recommendations Update to version 2.1.15 or later.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76371

Affected Products

Fireamp