What is CVE-2026-76356?
This CVE is a critical vulnerability affecting Splunk SOAR versions below 8.6.0. An unauthenticated attacker can spoof the source IP address in a crafted request to the Automation Broker notification endpoint, leading to arbitrary code execution on the host. Users must immediately upgrade to the latest version.
Azərbaycanca: Bu CVE Splunk SOAR-ın 8.6.0-dan aşağı versiyalarına təsir edən kritik boşluqdur. Doğrulanmamış hücumçu Automation Broker bildiriş nöqtəsinə saxta sorğu göndərərək mənbə IP ünvanını spoof edə və ev sahibində ixtiyari kod icra edə bilər. Splunk SOAR istifadəçiləri dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: shared vendor: Splunk
FAQ2
Which versions of Splunk SOAR are affected by CVE-2026-76356?
This critical vulnerability affects Splunk SOAR versions below 8.6.0.
What can an attacker achieve by exploiting CVE-2026-76356?
An unauthenticated attacker can execute arbitrary code on the host by sending a crafted request to the Automation Broker notification endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.