What is CVE-2026-76372?
CVE-2026-76372 is a vulnerability in Nmap Scanner versions below 3.0.15, where users with roles to edit, create, or run playbooks in Splunk SOAR could execute the scan network action in Safe Mode playbooks despite it being read-only. This could allow command execution or other unauthorized changes on the target system. Upgrading to version 3.0.15 or later is strongly recommended.
Azərbaycanca: CVE-2026-76372 Nmap Scanner-in 3.0.15-dən əvvəlki versiyalarında, Splunk SOAR daxilində müəyyən rollara malik istifadəçilərin Safe Mode playbook-da yalnız oxumaq üçün nəzərdə tutulmuş şəbəkə skan əməliyyatını icra edə bilməsi zəifliyidir. Bu, hədəf sistemdə komanda icrasına və digər icazəsiz dəyişikliklərə səbəb ola bilər. İstifadəçilərə Nmap Scanner-i ən azı 3.0.15 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Splunk
FAQ2
Which versions of Nmap Scanner are affected by CVE-2026-76372?
All versions of Nmap Scanner below 3.0.15 are affected by this vulnerability.
What unauthorized actions can result from CVE-2026-76372?
This vulnerability could allow command execution or other unauthorized changes on the target system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.