Command Execution Vulnerability in Nmap Scanner for Splunk SOAR
CVE-2026-76372
6.6MEDIUM
What is CVE-2026-76372?
An improper input validation flaw in the Nmap Scanner connection allows users with certain privileges to execute unauthorized commands. Users able to edit, create, or run playbooks on Splunk SOAR face risks when utilizing the network scan action within Safe Mode playbooks, which are incorrectly marked as read-only. The issue arises because this action accepts script parameters capable of executing write operations, leading to significant security implications. It is crucial for organizations to review playbook settings and ensure that script parameters are properly managed to mitigate potential risks.
Affected Version(s)
Nmap Scanner 3.0 < 3.0.15