IP Spoofing Vulnerability in Splunk SOAR Automation Broker
CVE-2026-76356

8.1HIGH

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76356?

In Splunk SOAR versions prior to 8.6.0, a flaw exists that allows unauthenticated users to spoof the source IP address when sending requests to the Automation Broker notification endpoint. This issue arises from the Automation Broker's trust in the client-supplied source IP header, enabling attackers to execute arbitrary code on the Splunk SOAR host. Such exploitation poses significant risks, including unauthorized access to sensitive data, degradation of system integrity, and potential disruptions to service availability. Organizations using this platform should prioritize upgrading to version 8.6.0 or later to mitigate these risks. For further details, refer to the Splunk advisory.

Affected Version(s)

Splunk SOAR 8.6 < 8.6.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NgocKhanh, CyStack
.