What is CVE-2026-76371?
CVE-2026-76371 is a vulnerability found in FireAMP versions prior to 2.1.15. A user with permissions to edit, create, or run playbooks in Splunk SOAR could execute the 'add listitem' action via Safe Mode, bypassing its read-only restriction and allowing unauthorized modifications to file lists. Immediate update to the patched version is strongly advised.
Azərbaycanca: CVE-2026-76371, FireAMP 2.1.15-dən əvvəlki versiyalarda aşkarlanmış zəiflikdir. Splunk SOAR mühitində Safe Mode playbook-lar vasitəsilə read-only olaraq təyin edilmiş 'add listitem' əməliyyatı icra edilərək fayl siyahılarında icazəsiz dəyişikliklərə səbəb ola bilər. İstifadəçilərə təcili olaraq FireAMP-i ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Splunk
FAQ2
Which versions of FireAMP are affected by CVE-2026-76371?
The vulnerability affects FireAMP versions prior to 2.1.15.
How can CVE-2026-76371 be exploited in Splunk SOAR?
A user with permissions to edit, create, or run playbooks can execute the 'add listitem' action via Safe Mode, bypassing its read-only restriction and making unauthorized modifications to file lists.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.