Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Splunk SOAR — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Splunk SOAR, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities affecting the Splunk SOAR product, specifically focusing on software weaknesses and security tags associated with the vendor. The collection compiles disclosed security flaws and their corresponding remediation guidance, covering the time range from the product’s initial release through the most recent security advisories. Readers can utilize this data to track the vendor’s advisory history, understand specific weakness classes such as injection or authentication failures, and review the product’s complete vulnerability timeline to assess its security posture over time.

Vendor: Splunk

CVE ID Title CVSS Severity Published
CVE-2026-76370 Information Disclosure through the REST API in Splunk SOAR CWE-863 4.3 Medium 2026-08-19
CVE-2026-76369 Path Traversal through Automation Broker in Splunk SOAR CWE-22 2.7 Low 2026-08-19
CVE-2026-76368 Missing Authorization through Playbooks in Splunk SOAR CWE-862 2.7 Low 2026-08-19
CVE-2026-76367 Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR CWE-79 4.0 Medium 2026-08-19
CVE-2026-76366 Information Disclosure through the REST API in Splunk SOAR CWE-200 6.5 Medium 2026-08-19
CVE-2026-76365 Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR CWE-74 6.5 Medium 2026-08-19
CVE-2026-76363 Structured Query Language Injection through the REST API in Splunk SOAR CWE-943 6.5 Medium 2026-08-19
CVE-2026-76364 Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR CWE-89 6.5 Medium 2026-08-19
CVE-2026-76362 Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR CWE-295 7.4 High 2026-08-19
CVE-2026-76361 Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR CWE-918 2.7 Low 2026-08-19
CVE-2026-76360 Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR CWE-862 4.3 Medium 2026-08-19
CVE-2026-76358 Path Traversal through App Installation Tar Extraction in Splunk SOAR CWE-22 6.5 Medium 2026-08-19
CVE-2026-76359 Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR CWE-22 6.5 Medium 2026-08-19
CVE-2026-76357 Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR CWE-22 7.6 High 2026-08-19
CVE-2026-76356 Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR CWE-290 8.1 High 2026-08-19
CVE-2026-20260 Log Injection through HTTP Request Paths in Splunk SOAR CWE-117 4.3 Medium 2026-06-10

All 16 known CVE vulnerabilities affecting Splunk SOAR with full Chinese analysis, references, and POCs where available.