VendorsSplunksoarall versions
Vulnerabilities

Splunk Soar

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2023-3997
Unauthenticated Log Injection In Splunk SOAR
Published 2023-07-31 · Modified
8.6EPSS 0.003
CVE-2026-76356
Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR
Published 2026-08-19 · Analyzed
8.1EPSS 0.006
CVE-2026-76357
Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR
Published 2026-08-19 · Analyzed
7.6EPSS 0.004
CVE-2026-76362
Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR
Published 2026-08-19 · Analyzed
7.4EPSS 0.002
CVE-2026-76358
Path Traversal through App Installation Tar Extraction in Splunk SOAR
Published 2026-08-19 · Analyzed
6.5EPSS 0.005
CVE-2026-76359
Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR
Published 2026-08-19 · Analyzed
6.5EPSS 0.005
CVE-2026-76363
Structured Query Language Injection through the REST API in Splunk SOAR
Published 2026-08-19 · Analyzed
6.5EPSS 0.004
CVE-2026-76364
Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR
Published 2026-08-19 · Analyzed
6.5EPSS 0.004
CVE-2026-76365
Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR
Published 2026-08-19 · Analyzed
6.5EPSS 0.004
CVE-2026-76366
Information Disclosure through the REST API in Splunk SOAR
Published 2026-08-19 · Analyzed
6.5EPSS 0.004
CVE-2026-76360
Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR
Published 2026-08-19 · Analyzed
4.3EPSS 0.003
CVE-2026-76370
Information Disclosure through the REST API in Splunk SOAR
Published 2026-08-19 · Analyzed
4.3EPSS 0.003
CVE-2026-76367
Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR
Published 2026-08-19 · Analyzed
4.0EPSS 0.002
CVE-2026-76369
Path Traversal through Automation Broker in Splunk SOAR
Published 2026-08-19 · Analyzed
2.7EPSS 0.004
CVE-2026-76361
Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR
Published 2026-08-19 · Analyzed
2.7EPSS 0.003
CVE-2026-76368
Missing Authorization through Playbooks in Splunk SOAR
Published 2026-08-19 · Analyzed
2.7EPSS 0.003