在 Splunk SOAR 8.6.0 之前的版本中,未认证用户可通过向 Automation Broker 通知端点构造恶意请求,伪造源 IP 地址,从而在 Splunk SOAR 主机上执行任意代码。该漏洞的成因在于 Splunk SOAR Automation Broker 将客户端提供的源 IP 地址头字段视为请求源自本地系统的凭证。成功利用此漏洞可能导致所有相关数据泄露、系统完整性受损以及服务可用性中断。更多信息请参阅 Splunk 文档中的《关于 Splunk SOAR Automation Broke
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | Splunk SOAR | 8.6< 8.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Splunk | Splunk SOAR | 8.6 ~ 8.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76312 | 9.4 CRITICAL | Improper Access Control through Embedded Reports in Splunk Enterprise |
| CVE-2026-76310 | 9.4 CRITICAL | Improper Access Control through Embedded Report REST API Requests in Splunk Enterprise |
| CVE-2026-76311 | 9.4 CRITICAL | Improper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise |
| CVE-2026-76404 | 9.1 CRITICAL | Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server |
| CVE-2026-76319 | 8.8 HIGH | Remote Code Execution (RCE) through Federated Search in Splunk Enterprise |
| CVE-2026-76316 | 8.8 HIGH | Stored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise |
| CVE-2026-76351 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secu |
| CVE-2026-76350 | 8.8 HIGH | Improper Privilege Management through PDF Attachments for Email Alert Actions in Splunk En |
| CVE-2026-76389 | 8.8 HIGH | Server-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for En |
| CVE-2026-76253 | 8.8 HIGH | Privilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterpr |
| CVE-2026-76315 | 8.8 HIGH | Code Injection through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76395 | 8.8 HIGH | Remote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading |
| CVE-2026-76313 | 8.8 HIGH | Remote Code Execution (RCE) through the REST API in Splunk Enterprise |
| CVE-2026-76335 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76352 | 8.8 HIGH | Improper Authorization through the REST API in Splunk Enterprise |
| CVE-2026-76317 | 8.8 HIGH | Path Traversal through the Lookup Configuration REST API in Splunk Enterprise |
| CVE-2026-76314 | 8.8 HIGH | Remote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise |
| CVE-2026-76259 | 8.8 HIGH | Improper Privilege Management on the Management Port in Splunk Enterprise for Windows |
| CVE-2026-76391 | 8.3 HIGH | Improper Privilege Management through Agent Run History in Splunk AI Toolkit |
| CVE-2026-76394 | 8.3 HIGH | Missing Authorization in Container and Connection Management through the REST API in Splun |
Showing top 20 of 110 CVEs. View all on vendor page → →
No comments yet