What is CVE-2026-76359?
This critical vulnerability affects Splunk SOAR versions below 8.6.0, allowing a user with the Administrator role to exploit a path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended directory. Immediate upgrade to version 8.6.0 or later is strongly recommended to mitigate the risk.
Azərbaycanca: Bu kritik zəiflik Splunk SOAR-ın 8.6.0-dan aşağı versiyalarına təsir edir və Administrator rolu olan istifadəçiyə Universal Forwarder quraşdırıcısında path traversal vasitəsilə faylları nəzərdə tutulan qovluqdan kənara yazmağa imkan verir. Təhlükəsizlik üçün dərhal Splunk SOAR-ı 8.6.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Splunk
FAQ2
Which versions of Splunk SOAR are affected by CVE-2026-76359?
This critical vulnerability affects versions below 8.6.0.
What should be done to mitigate CVE-2026-76359?
Immediate upgrade to version 8.6.0 or later is strongly recommended to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.