VYPR

Splunk App Soar

by Splunk

CVEs (19)

  • CVE-2026-76356HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.01

    In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation…

  • CVE-2026-76362HigAug 19, 2026
    risk 0.48cvss 7.4epss 0.00

    In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server could access or modify all relevant data exchanged through that credential manager.…

  • CVE-2026-76366MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible…

  • CVE-2026-76364MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database through custom function results, allowing for reading all relevant data stored in the…

  • CVE-2026-76363MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database and create, read, update, or delete all data in the database. The vulnerability is possible…

  • CVE-2025-22621MedJan 7, 2025
    risk 0.42cvss 6.4epss 0.00

    In versions 1.0.67 and lower of the Splunk App for SOAR, the Splunk documentation for that app recommended adding the `admin_all_objects` capability to the `splunk_app_soar` role. This addition could lead to improper access control for a low-privileged user that does not hold…

  • CVE-2026-76373MedAug 19, 2026
    risk 0.35cvss 5.4epss 0.00

    In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read…

  • CVE-2026-76375MedAug 19, 2026
    risk 0.33cvss 5.0epss 0.00

    In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in…

  • CVE-2026-76386MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected…

  • CVE-2026-76385MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked…

  • CVE-2026-76382MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking the deflate item action, because the action's password parameter is not masked and is shown in cleartext in…

  • CVE-2026-76379MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in…

  • CVE-2026-76377MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext…

  • CVE-2026-76376MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive AWS credentials by invoking an action that accepts the credentials parameter, because the parameter is not masked and is shown in cleartext…

  • CVE-2026-76374MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more…

  • CVE-2026-76370MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names and identifiers of tenants that fall outside the role scope for that user. The vulnerability is possible because…

  • CVE-2026-76371LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The…

  • CVE-2026-76368LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata about a playbook repository that they are not authorized to view. The vulnerability is possible because Playbook History does not check repository…

  • CVE-2026-76361LowAug 19, 2026
    risk 0.18cvss 2.7epss 0.00

    In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary destinations and determine whether internal hosts and ports…