« Back to list

Splunk

Splunk Soar: vulnerabilities and CVEs

Splunk Soar has 26 published vulnerabilities, 25 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs26
Last 12 months25
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-76386Medium (4.3)0.19%—Aug 19, 2026
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update…
CVE-2026-76383Medium (4.3)0.21%—Aug 19, 2026
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or…
CVE-2026-76380Medium (4.3)0.19%—Aug 19, 2026
In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or…
CVE-2026-76379Medium (4.3)0.19%—Aug 19, 2026
In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the…
CVE-2026-76378Medium (4.3)0.19%—Aug 19, 2026
In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action,…
CVE-2026-76377Medium (4.3)0.19%—Aug 19, 2026
In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's…
CVE-2026-76375Medium (5)0.29%—Aug 19, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process…
CVE-2026-76374Medium (4.3)0.29%—Aug 19, 2026
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by…
CVE-2026-76371Low (2.7)0.28%—Aug 19, 2026
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which…
CVE-2026-76370Medium (4.3)0.27%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names and identifiers of tenants that fall outside the role…
CVE-2026-76369Low (2.7)0.35%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads…
CVE-2026-76368Low (2.7)0.30%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata about a playbook repository that they are not authorized to view. The vulnerability is…
CVE-2026-76367Medium (4)0.20%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a note and run it in the browser of another user when that user opens the note. The stored…
CVE-2026-76366Medium (6.5)0.39%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available…
CVE-2026-76365Medium (6.5)0.40%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom list…
CVE-2026-76364Medium (6.5)0.40%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom function…
CVE-2026-76363Medium (6.5)0.41%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database and create, read, update, or delete…
CVE-2026-76362High (7.4)0.21%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server could access or modify…
CVE-2026-76361Low (2.7)0.30%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary…
CVE-2026-76360Medium (4.3)0.27%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users.…
CVE-2026-76359Medium (6.5)0.52%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended installation directory.…
CVE-2026-76358Medium (6.5)0.52%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the intended temporary directory. The vulnerability is a path traversal in…
CVE-2026-76357High (7.6)0.43%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is…
CVE-2026-76356High (8.1)0.61%—Aug 19, 2026
In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The…
CVE-2026-20260Medium (4.3)0.20%—Jun 10, 2026
In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR application log files…
CVE-2023-3997High (7.8)0.29%—Jul 31, 2023
Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1078 Valid Accounts1
  3. T1190 Exploit Public-Facing Application1
  4. T1210 Exploitation of Remote Services1
  5. T1552.007 Container API1
  6. T1557 Adversary-in-the-Middle1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Splunk