Stored Cross-Site Scripting Vulnerability in Splunk SOAR by Splunk
CVE-2026-76367
4MEDIUM
What is CVE-2026-76367?
In Splunk SOAR versions earlier than 8.6.0, a vulnerability exists that allows users with the 'Incident Commander' role to inject JavaScript into notes. When another user views these notes, the malicious JavaScript executes in their browser, leading to potential security breaches. This occurs due to the lack of proper sanitization; Splunk SOAR processes note content as HTML without adequately filtering it when formats are switched. Attackers must trick users into opening these notes, highlighting the need for cautious user interaction and awareness.
Affected Version(s)
Splunk SOAR 8.6 < 8.6.0