SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76367

MEDIUM · CVSS 4 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk SOAR versions prior to 8.6.0 are vulnerable to a stored Cross-Site Scripting (XSS) flaw, allowing users with the "Incident Commander" role to embed malicious JavaScript in notes that can execute in the browsers of other users. This vulnerability can lead to unauthorized actions or data exposure if an affected user is tricked into opening the compromised note. Organizations using Splunk SOAR should prioritize upgrading to version 8.6.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-76367
Severity
MEDIUM
CVSS
4
EPSS
0.15%
Java

Original NVD Description

In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a note and run it in the browser of another user when that user opens the note. The stored Cross-Site Scripting (XSS) vulnerability is possible because Splunk SOAR can treat existing note content as Hypertext Markup Language (HTML) without sanitizing that content when the note format changes. The vulnerability requires the attacker to phish the affected user by tricking them into initiating a request within their browser. The user who holds the "Incident Commander" Splunk SOAR role should not be able to exploit the vulnerability at will. For more information see Manage roles and permissions in Splunk SOAR (Cloud) (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)