Stored Cross-Site Scripting Vulnerability in Splunk SOAR by Splunk
CVE-2026-76367

4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76367?

In Splunk SOAR versions earlier than 8.6.0, a vulnerability exists that allows users with the 'Incident Commander' role to inject JavaScript into notes. When another user views these notes, the malicious JavaScript executes in their browser, leading to potential security breaches. This occurs due to the lack of proper sanitization; Splunk SOAR processes note content as HTML without adequately filtering it when formats are switched. Attackers must trick users into opening these notes, highlighting the need for cautious user interaction and awareness.

Affected Version(s)

Splunk SOAR 8.6 < 8.6.0

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.