PT-2026-78799 · Splunk · Nmap Scanner
CVE-2026-76372
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
6.6
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Nmap Scanner versions prior to 3.0.15
Description
A user with permissions to edit, create, or run playbooks in Splunk SOAR can execute the scan network action within a Safe Mode playbook, despite the action being marked as read-only. This occurs because the connector action manifest incorrectly classifies the scan network action as read-only, while it still accepts script parameters that can perform write operations. This flaw could allow for command execution or unauthorized changes on a target system via Nmap Scripting Engine scripts.
Recommendations
Update Nmap Scanner to version 3.0.15 or later.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nmap Scanner