SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-76369

LOW · CVSS 2.7 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

In Splunk SOAR versions prior to 8.6.0, users with the OnPrem Broker role can exploit a vulnerability that allows them to write files outside the designated Automation Broker log directory due to improper handling of crafted filename inputs. This could lead to unauthorized file access or manipulation, posing a risk to system integrity. Organizations using affected versions of Splunk SOAR should prioritize patching to mitigate potential security risks associated with this vulnerability.

CVE
CVE-2026-76369
Severity
LOW
CVSS
2.7
EPSS
0.26%

Original NVD Description

In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For more information see Manage roles and permissions in Splunk SOAR (Cloud) (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) and About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)