Splunk
Splunk Soar: vulnerabilidades y CVE
Splunk Soar tiene 26 vulnerabilidades publicadas, 25 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE26
Últimos 12 meses25
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76386 | Media (4.3) | 0.19% | — | 19 ago 2026 | In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update… |
| CVE-2026-76383 | Media (4.3) | 0.21% | — | 19 ago 2026 | In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or… |
| CVE-2026-76380 | Media (4.3) | 0.19% | — | 19 ago 2026 | In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or… |
| CVE-2026-76379 | Media (4.3) | 0.19% | — | 19 ago 2026 | In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the… |
| CVE-2026-76378 | Media (4.3) | 0.19% | — | 19 ago 2026 | In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action,… |
| CVE-2026-76377 | Media (4.3) | 0.19% | — | 19 ago 2026 | In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's… |
| CVE-2026-76375 | Media (5) | 0.29% | — | 19 ago 2026 | In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process… |
| CVE-2026-76374 | Media (4.3) | 0.29% | — | 19 ago 2026 | In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by… |
| CVE-2026-76371 | Baja (2.7) | 0.28% | — | 19 ago 2026 | In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which… |
| CVE-2026-76370 | Media (4.3) | 0.27% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names and identifiers of tenants that fall outside the role… |
| CVE-2026-76369 | Baja (2.7) | 0.35% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads… |
| CVE-2026-76368 | Baja (2.7) | 0.30% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata about a playbook repository that they are not authorized to view. The vulnerability is… |
| CVE-2026-76367 | Media (4) | 0.20% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a note and run it in the browser of another user when that user opens the note. The stored… |
| CVE-2026-76366 | Media (6.5) | 0.39% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available… |
| CVE-2026-76365 | Media (6.5) | 0.40% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom list… |
| CVE-2026-76364 | Media (6.5) | 0.40% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom function… |
| CVE-2026-76363 | Media (6.5) | 0.41% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database and create, read, update, or delete… |
| CVE-2026-76362 | Alta (7.4) | 0.21% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server could access or modify… |
| CVE-2026-76361 | Baja (2.7) | 0.30% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary… |
| CVE-2026-76360 | Media (4.3) | 0.27% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users.… |
| CVE-2026-76359 | Media (6.5) | 0.52% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended installation directory.… |
| CVE-2026-76358 | Media (6.5) | 0.52% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the intended temporary directory. The vulnerability is a path traversal in… |
| CVE-2026-76357 | Alta (7.6) | 0.43% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is… |
| CVE-2026-76356 | Alta (8.1) | 0.61% | — | 19 ago 2026 | In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The… |
| CVE-2026-20260 | Media (4.3) | 0.20% | — | 10 jun 2026 | In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR application log files… |
| CVE-2023-3997 | Alta (7.8) | 0.29% | — | 31 jul 2023 | Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.