What is CVE-2026-76363?
This vulnerability affects Splunk SOAR versions below 8.6.0, allowing a user with the "Automation Engineer" role to execute arbitrary SQL statements against the database. This could lead to unauthorized creation, reading, updating, or deletion of all data. Immediate upgrade to version 8.6.0 or later is strongly recommended.
Azərbaycanca: Bu zəiflik Splunk SOAR platformasının 8.6.0-dan aşağı versiyalarına təsir edir və "Automation Engineer" roluna malik istifadəçiyə məlumat bazasında ixtiyari SQL sorğuları icra etməyə imkan verir. Nəticədə hücumçu verilənlər bazasındakı bütün məlumatları oxuya, yarada, yeniləyə və ya silə bilər. Zəiflikdən qorunmaq üçün dərhal 8.6.0 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Splunk
FAQ2
What versions of Splunk SOAR are affected by CVE-2026-76363?
This vulnerability affects Splunk SOAR versions below 8.6.0.
What role is required to exploit CVE-2026-76363?
The vulnerability can be exploited by a user with the "Automation Engineer" role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.