IP Spoofing Vulnerability in Splunk SOAR Automation Broker
CVE-2026-76356
8.1HIGH
What is CVE-2026-76356?
In Splunk SOAR versions prior to 8.6.0, a flaw exists that allows unauthenticated users to spoof the source IP address when sending requests to the Automation Broker notification endpoint. This issue arises from the Automation Broker's trust in the client-supplied source IP header, enabling attackers to execute arbitrary code on the Splunk SOAR host. Such exploitation poses significant risks, including unauthorized access to sensitive data, degradation of system integrity, and potential disruptions to service availability. Organizations using this platform should prioritize upgrading to version 8.6.0 or later to mitigate these risks. For further details, refer to the Splunk advisory.
Affected Version(s)
Splunk SOAR 8.6 < 8.6.0