What is CVE-2026-76364?
CVE-2026-76364: In Splunk SOAR versions below 8.6.0, users with the 'Automation Engineer' role can execute arbitrary SQL statements against the SOAR database via custom function results, enabling full data read access. This vulnerability could lead to unauthorized data exposure by privileged users. Upgrading to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-76364: Splunk SOAR 8.6.0-dən aşağı versiyalarda 'Automation Engineer' roluna malik istifadəçilər xüsusi funksiya nəticələri vasitəsilə arzuolunmaz SQL sorğuları icra edərək verilənlər bazasındakı bütün məlumatları oxuya bilər. Bu zəiflik yüksək səlahiyyətli istifadəçilər tərəfindən daxili məlumat sızmasına səbəb ola bilər. Splunk SOAR-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Splunk
FAQ2
What role is required to exploit the CVE-2026-76364 vulnerability in Splunk SOAR?
The 'Automation Engineer' role is required to exploit this vulnerability.
To what version should Splunk SOAR be upgraded to mitigate CVE-2026-76364?
It is recommended to upgrade Splunk SOAR to version 8.6.0 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.