Command Execution Vulnerability in Nmap Scanner for Splunk SOAR
CVE-2026-76372

6.6MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76372?

An improper input validation flaw in the Nmap Scanner connection allows users with certain privileges to execute unauthorized commands. Users able to edit, create, or run playbooks on Splunk SOAR face risks when utilizing the network scan action within Safe Mode playbooks, which are incorrectly marked as read-only. The issue arises because this action accepts script parameters capable of executing write operations, leading to significant security implications. It is crucial for organizations to review playbook settings and ensure that script parameters are properly managed to mitigate potential risks.

Affected Version(s)

Nmap Scanner 3.0 < 3.0.15

References

CVSS V3.1

Score:
6.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.