SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76357

HIGH · CVSS 7.6 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

In Splunk SOAR versions prior to 8.6.0, an authenticated user lacking an assigned role can exploit the REST API to submit a malicious file path, potentially leading to arbitrary code execution. This vulnerability arises from insufficient access controls and improper validation of user-supplied input. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized code execution.

CVE
CVE-2026-76357
Severity
HIGH
CVSS
7.6
EPSS
0.33%

Original NVD Description

In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role for the request and does not restrict the user-supplied file path to the intended temporary directory. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) and Splunk SOAR (On-premises) security information (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/introduction-to-splunk-soar-on-premises/splunk-soar-on-premises-security-information) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)