Description
In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the FireAMP connector action manifest classifies the add listitem action as read-only even though the action updates file lists. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.
Published: 2026-08-19
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A misconfigured permission setting in the FireAMP connector allows a user with the ability to edit or run playbooks to execute the add listitem action in Safe Mode, even though the action is labeled read‑only. This results in unauthorized modifications to file lists, effectively changing security‑critical configuration data. The weakness is a classic permission assignment error identified as CWE‑732.

Affected Systems

The issue affects Splunk FireAMP connectors in Splunk SOAR versions earlier than 2.1.15. Any deployment of the FireAMP app that has not been updated to the fixed release is vulnerable.

Risk and Exploitability

The CVSS score of 2.7 indicates a low severity threat, and the EPSS score is not available, implying a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need a role that permits editing or executing playbooks, meaning the attack vector is internal and restricted to privileged users. Because the action is run while marked read‑only, exploitation requires only that the user can trigger the playbook, so the risk is largely tied to misconfigured role assignments rather than an external attack surface.

Generated by OpenCVE AI on August 20, 2026 at 10:43 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the FireAMP app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-cloud) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in the product status.
  • If an immediate upgrade is not feasible, turn off or remove the FireAMP app for Splunk SOAR to block the action from running.
  • Review and correct playbook role permissions to ensure that only authorized users can edit or run playbooks, thereby preventing unauthorized modification of file lists.

Generated by OpenCVE AI on August 20, 2026 at 10:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk fireamp
Vendors & Products Splunk
Splunk fireamp

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the FireAMP connector action manifest classifies the add listitem action as read-only even though the action updates file lists. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.
Title Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOAR
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:32.930Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76371

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:22.887

Modified: 2026-08-20T17:19:46.410

Link: CVE-2026-76371

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource