What is CVE-2026-76365?
In Splunk SOAR versions below 8.6.0, a user with the 'Automation Engineer' role can execute arbitrary SQL statements against the database via custom list retrieval in a playbook. This vulnerability allows create, read, update, and delete operations on data, posing a significant risk of data compromise. Upgrading to version 8.6.0 or later is recommended.
Azərbaycanca: Splunk SOAR-ın 8.6.0-dan aşağı versiyalarında 'Automation Engineer' roluna malik istifadəçi, playbook-da xüsusi siyahı əldə etmə funksiyası vasitəsilə verilənlər bazasında ixtiyari SQL sorğuları icra edə bilər. Bu zəiflik verilənlər üzərində yaratma, oxuma, yeniləmə və silmə əməliyyatlarına imkan yaradır ki, bu da ciddi məlumat sızmasına səbəb ola bilər. Splunk SOAR-ı ən azı 8.6.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Splunk
FAQ2
What role is required to exploit the SQL injection vulnerability in Splunk SOAR?
The 'Automation Engineer' role is required to exploit this vulnerability.
To which version should Splunk SOAR be upgraded to fix CVE-2026-76365?
Upgrading to version 8.6.0 or later is recommended to fix this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.