VYPR

SOAR

by Splunk

CVEs (10)

  • CVE-2023-3997HigJul 31, 2023
    risk 0.56cvss 8.6epss 0.00

    Splunk SOAR versions lower than 6.1.0 are indirectly affected by a potential vulnerability accessed through the user’s terminal. A third party can send Splunk SOAR a maliciously crafted web request containing special ANSI characters to cause log file poisoning. When a terminal…

  • CVE-2026-76357HigAug 19, 2026
    risk 0.49cvss 7.6epss 0.00

    In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role…

  • CVE-2026-76372MedAug 19, 2026
    risk 0.43cvss 6.6epss 0.00

    In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network action in a Safe Mode playbook while that action is listed as read-only, which could allow for command execution or other changes on a…

  • CVE-2026-76365MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom list retrieval in a playbook, allowing for create, read, update, and…

  • CVE-2026-76359MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended installation directory. The vulnerability is possible because the Universal…

  • CVE-2026-76358MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation to write files outside the intended temporary directory. The vulnerability is a path traversal in the archive extraction routine, which does not validate that…

  • CVE-2026-76360MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing authorization check, where the…

  • CVE-2026-20260MedJun 10, 2026
    risk 0.28cvss 4.3epss 0.00

    In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR application log files through specially crafted HTTP request paths, which a…

  • CVE-2026-76367MedAug 19, 2026
    risk 0.26cvss 4.0epss 0.00

    In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a note and run it in the browser of another user when that user opens the note. The stored Cross-Site Scripting (XSS) vulnerability is possible because…

  • CVE-2026-76369LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For…