What is CVE-2026-76367?
CVE-2026-76367 is a stored Cross-Site Scripting (XSS) vulnerability in Splunk SOAR versions below 8.6.0, where a user with the 'Incident Commander' role can inject JavaScript into notes that execute in another user's browser when the note is opened. This could lead to data theft, and upgrading to version 8.6.0 or later is recommended.
Azərbaycanca: CVE-2026-76367 Splunk SOAR-ın 8.6.0-dan aşağı versiyalarında "Incident Commander" roluna malik istifadəçinin qeydlərə JavaScript kodu yerləşdirərək, həmin qeydi açan digər istifadəçinin brauzerində icra etdirməsinə imkan verən saxlanılmış XSS zəifliyidir. Bu, həssas məlumatların oğurlanmasına səbəb ola bilər, Splunk SOAR-ı ən azı 8.6.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Splunk
FAQ2
Which versions of Splunk SOAR are affected by CVE-2026-76367?
This stored XSS vulnerability affects Splunk SOAR versions below 8.6.0.
What role must an attacker have to exploit CVE-2026-76367?
The attacker must have the 'Incident Commander' role.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.