Server-Side Request Forgery Vulnerability in Splunk SOAR by Splunk
CVE-2026-76361
2.7LOW
What is CVE-2026-76361?
In certain versions of Splunk SOAR, an SSRF vulnerability allows users with the Administrator role to exploit the /rest/support/connectivity/.../check_connectivity endpoint. This oversight permits unauthorized outbound network connections to arbitrary destinations, compromising internal host integrity and exposing sensitive configurations. The vulnerability arises from insufficient validation of destination addresses before the application initiates connections. For a thorough examination of roles and permissions, refer to the Splunk documentation.
Affected Version(s)
Splunk SOAR 8.6 < 8.6.0