{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/splunk-soar/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-76356"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Splunk SOAR"],"_cs_severities":["high"],"_cs_tags":["rce","vulnerability","splunk"],"_cs_type":"advisory","_cs_vendors":["Splunk"],"content_html":"\u003cp\u003eSplunk SOAR versions below 8.6.0 contain a critical vulnerability in the Automation Broker notification endpoint. The vulnerability arises because the Automation Broker improperly trusts client-supplied source IP address headers to verify the origin of a request. An unauthenticated attacker can craft an HTTP request that spoofs the source IP to appear as though it originates from the local host, bypassing intended access controls. Successful exploitation enables the execution of arbitrary code on the underlying host, which can lead to full system compromise, data exfiltration, and service disruption. Defenders should prioritize patching Splunk SOAR instances to version 8.6.0 or later to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-76356 allows an unauthenticated, remote attacker to execute arbitrary code on the Splunk SOAR host. This results in complete compromise of the SOAR platform, potential access to highly sensitive security data stored within the SOAR environment, and the ability to pivot to other integrated security tools or managed internal systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Splunk SOAR instances to version 8.6.0 or higher immediately.\u003c/li\u003e\n\u003cli\u003eUntil patching is possible, restrict network access to the Automation Broker notification endpoint to only authorized, trusted IP ranges at the network perimeter or application firewall level.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for requests to the Automation Broker endpoint originating from unexpected or external IP addresses that attempt to manipulate header fields.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-19T22:43:19Z","date_published":"2026-08-19T22:43:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-splunk-soar-rce/","summary":"Splunk SOAR versions prior to 8.6.0 are vulnerable to remote code execution because the Automation Broker fails to validate client-supplied source IP headers, allowing unauthenticated attackers to spoof local requests.","title":"Unauthenticated Remote Code Execution in Splunk SOAR via Automation Broker","url":"https://feed.craftedsignal.io/briefs/2026-08-splunk-soar-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Splunk SOAR","version":"https://jsonfeed.org/version/1.1"}