PT-2026-78799 · Splunk · Nmap Scanner

CVE-2026-76372

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v3.1

6.6

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nmap Scanner versions prior to 3.0.15
Description A user with permissions to edit, create, or run playbooks in Splunk SOAR can execute the scan network action within a Safe Mode playbook, despite the action being marked as read-only. This occurs because the connector action manifest incorrectly classifies the scan network action as read-only, while it still accepts script parameters that can perform write operations. This flaw could allow for command execution or unauthorized changes on a target system via Nmap Scripting Engine scripts.
Recommendations Update Nmap Scanner to version 3.0.15 or later.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76372

Affected Products

Nmap Scanner