SQL Injection Vulnerability in Splunk SOAR Affects Data Integrity
CVE-2026-76365

6.5MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76365?

In Splunk SOAR versions prior to 8.6.0, a security vulnerability exists where users with the 'Automation Engineer' role can execute arbitrary SQL commands on the Splunk SOAR database. This issue arises when creating custom list databases, allowing unauthorized access to sensitive database operations—such as creation, reading, updating, and deletion of data. The root cause is an improper construction of database lookups, where user-supplied list names are utilized in an unbound manner. This flaw poses significant risks to data integrity and user privacy.

Affected Version(s)

Splunk SOAR 8.6 < 8.6.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.