PT-2026-78798 · Splunk · Fireamp
CVE-2026-76371
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
FireAMP versions prior to 2.1.15
Description
A user with permissions to edit, create, or run playbooks in Splunk SOAR can execute the
add listitem action within a Safe Mode playbook. This is possible because the FireAMP connector action manifest incorrectly classifies the add listitem action as read-only, despite the fact that it updates file lists, potentially leading to unauthorized modifications of those lists.Recommendations
Update to version 2.1.15 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fireamp