Unauthorized Changes in Splunk SOAR due to FireAMP Connector Flaw
CVE-2026-76371
2.7LOW
What is CVE-2026-76371?
A vulnerability in FireAMP versions prior to 2.1.15 allows users with roles that can edit or run playbooks in Splunk SOAR to execute the add listitem action in a Safe Mode playbook incorrectly labeled as read-only. This misclassification permits unauthorized modifications to file lists, posing a significant risk to the integrity of playbook functions. For further details, consult the Splunk documentation on managing playbooks.
Affected Version(s)
FireAMP 2.1 < 2.1.15