Description
In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation Broker trusts a client-supplied source IP address header as proof that the request originates from the local system. Successful exploitation can expose all relevant data, affect system integrity, and disrupt service availability. For more information see About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.
Published: 2026-08-19
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to spoof the client‑supplied source IP header in a request to the Automation Broker notification endpoint and cause arbitrary code execution on the Splunk SOAR host. Because the broker trusts this header as proof of local origin, the attacker can run code with the host’s privileges, exposing sensitive data, corrupting system integrity, and potentially disrupting service availability.

Affected Systems

Splunk SOAR versions prior to 8.6.0 are affected. The flaw resides in the Automation Broker component that processes notification requests.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. The most probable attack vector is an external or remote attacker submitting a crafted request to the exposed endpoint, exploiting the lack of authentication and the trust placed in the source IP header.

Generated by OpenCVE AI on August 20, 2026 at 10:10 UTC.

Remediation

Vendor Solution

Upgrade Splunk SOAR to 8.6.0 or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk SOAR to version 8.6.0 or newer, which removes the trust in the source IP header.
  • Block or restrict access to the Automation Broker notification endpoint to trusted networks or hosts using firewall rules or network segmentation.
  • Monitor the broker logs for anomalous requests, especially those containing forged source IP headers, and alert on suspicious activity.

Generated by OpenCVE AI on August 20, 2026 at 10:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk soar
CPEs cpe:2.3:a:splunk:soar:*:*:*:*:cloud:*:*:*
cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:*
Vendors & Products Splunk soar

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Vendors & Products Splunk
Splunk splunk

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation Broker trusts a client-supplied source IP address header as proof that the request originates from the local system. Successful exploitation can expose all relevant data, affect system integrity, and disrupt service availability. For more information see About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.
Title Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-27T16:24:58.958Z

Reserved: 2026-08-19T12:02:03.628Z

Link: CVE-2026-76356

cve-icon Vulnrichment

Updated: 2026-08-27T16:17:43.219Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:20.727

Modified: 2026-08-27T17:20:16.633

Link: CVE-2026-76356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:54Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing