What is CVE-2026-76358?
In Splunk SOAR versions below 8.6.0, a user with app-install privileges can exploit a path traversal in the archive extraction routine to write files outside the intended temporary directory. This allows arbitrary file placement on the system. Upgrading to version 8.6.0 or later is recommended.
Azərbaycanca: Splunk SOAR-ın 8.6.0-dan əvvəlki versiyalarında, tətbiq quraşdırma səlahiyyəti olan istifadəçi arxiv çıxarışı zamanı path traversal zəifliyindən istifadə edərək müvəqqəti qovluqdan kənar fayllar yaza bilər. Bu, təcavüzkara sistemdə özbaşına fayl yerləşdirməyə imkan verir. Splunk SOAR-ı ən azı 8.6.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Splunk
FAQ2
What privilege must an attacker have to exploit the path traversal vulnerability in Splunk SOAR?
The attacker must be a user with app-install privileges.
Which version of Splunk SOAR resolves the CVE-2026-76358 vulnerability?
Upgrading to version 8.6.0 or later resolves this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.