Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-76369

In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For more information see Manage roles and permissions in Splunk SOAR (Cloud) (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) and About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 17.9%
CVSS Severity
CVSS v3 Score 2.7
Products affected by CVE-2026-76369
  • Splunk » Soar » Version: N/A
    cpe:2.3:a:splunk:soar:-
  • Splunk » Soar » Version: 6.0.1.123902
    cpe:2.3:a:splunk:soar:6.0.1.123902
  • Splunk » Soar » Version: 6.1.0.131
    cpe:2.3:a:splunk:soar:6.1.0.131


Contact Us

Shodan ® - All rights reserved