What is CVE-2026-76369?
In Splunk SOAR versions below 8.6.0, a user with the OnPrem Broker role can write files outside the intended Automation Broker log directory. This vulnerability arises because Automation Broker log uploads accept crafted filenames before writing logs. Upgrading Splunk SOAR to version 8.6.0 or higher is recommended.
Azərbaycanca: Splunk SOAR sisteminin 8.6.0 versiyasından əvvəlki versiyalarında, 'OnPrem Broker' roluna malik istifadəçi Automation Broker log kataloqu xaricində fayl yaza bilər. Bu boşluq log yükləmələrində fayl adlarının düzgün yoxlanılmaması səbəbindən yaranır. Splunk SOAR-ı 8.6.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: Splunk
FAQ2
Which user role does CVE-2026-76369 affect in Splunk SOAR?
This vulnerability affects users with the 'OnPrem Broker' role.
What is the remediation for CVE-2026-76369?
It is recommended to upgrade Splunk SOAR to version 8.6.0 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.