What is CVE-2026-76357?
CVE-2026-76357 is a critical vulnerability in Splunk SOAR versions below 8.6.0. An authenticated user with no assigned role can submit a crafted file path to the REST API to achieve arbitrary code execution. Users should immediately upgrade to version 8.6.0 or later.
Azərbaycanca: CVE-2026-76357 Splunk SOAR məhsulunda 8.6.0-dan aşağı versiyalarda aşkar edilmiş kritik zəiflikdir. Heç bir rolu olmayan autentifikasiya olunmuş istifadəçi REST API-ə xüsusi hazırlanmış fayl yolu göndərərək ixtiyari kod icrası həyata keçirə bilər. Splunk SOAR istifadəçiləri dərhal 8.6.0 və ya daha yuxarı versiyaya yeniləmə aparmalıdırlar.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Splunk
FAQ2
Which versions of Splunk SOAR are affected by CVE-2026-76357?
CVE-2026-76357 affects all Splunk SOAR versions below 8.6.0.
How can an authenticated user with no assigned role exploit this vulnerability?
The user can submit a crafted file path to the REST API to achieve arbitrary code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.