Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Splunk SOAR — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Splunk SOAR, with AI-generated Chinese analysis, references, and POCs.

This page provides an aggregation of publicly disclosed security vulnerabilities associated with the Splunk SOAR product, categorized under general software weakness types. It compiles a comprehensive collection of security flaws affecting the platform, covering advisory releases and public exposure data from 2019 through early 2025. Visitors to this resource can efficiently track Splunk’s security advisory history, analyze the specific characteristics and impact of recurring weakness classes within the SOAR environment, and investigate the complete vulnerability timeline for any specific version or component. The content is structured to support security professionals, incident responders, and system administrators in assessing risk exposure and prioritizing remediation efforts based on historical data. By centralizing these details, the page eliminates the need to cross-reference multiple external sources, offering a single point of reference for understanding the security posture of the software over time. This approach facilitates better informed decision-making regarding patch management and configuration hardening. Users can filter the available data by severity, component, or release date to isolate relevant threats pertinent to their specific infrastructure deployments. The aggregated information serves as a historical record, highlighting patterns in defect discovery and resolution, which aids in anticipating potential future issues. This resource is intended for informational purposes to enhance situational awareness and support proactive security hygiene within organizations utilizing the Splunk SOAR platform.

Vendor: Splunk

CVE ID Title CVSS Severity Published
CVE-2026-76370 Information Disclosure through the REST API in Splunk SOAR CWE-863 4.3 Medium 2026-08-19
CVE-2026-76369 Path Traversal through Automation Broker in Splunk SOAR CWE-22 2.7 Low 2026-08-19
CVE-2026-76368 Missing Authorization through Playbooks in Splunk SOAR CWE-862 2.7 Low 2026-08-19
CVE-2026-76367 Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR CWE-79 4.0 Medium 2026-08-19
CVE-2026-76366 Information Disclosure through the REST API in Splunk SOAR CWE-200 6.5 Medium 2026-08-19
CVE-2026-76365 Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR CWE-74 6.5 Medium 2026-08-19
CVE-2026-76363 Structured Query Language Injection through the REST API in Splunk SOAR CWE-943 6.5 Medium 2026-08-19
CVE-2026-76364 Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR CWE-89 6.5 Medium 2026-08-19
CVE-2026-76362 Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR CWE-295 7.4 High 2026-08-19
CVE-2026-76361 Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR CWE-918 2.7 Low 2026-08-19
CVE-2026-76360 Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR CWE-862 4.3 Medium 2026-08-19
CVE-2026-76358 Path Traversal through App Installation Tar Extraction in Splunk SOAR CWE-22 6.5 Medium 2026-08-19
CVE-2026-76359 Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR CWE-22 6.5 Medium 2026-08-19
CVE-2026-76357 Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR CWE-22 7.6 High 2026-08-19
CVE-2026-76356 Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR CWE-290 8.1 High 2026-08-19
CVE-2026-20260 Log Injection through HTTP Request Paths in Splunk SOAR CWE-117 4.3 Medium 2026-06-10

All 16 known CVE vulnerabilities affecting Splunk SOAR with full Chinese analysis, references, and POCs where available.