CVE-2026-76363: Structured Query Language Injection through the REST API in Splunk SOAR
In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Query Language (SQL) statements against the Splunk SOAR database and create, read, update, or delete all data in the database. The vulnerability is possible because Splunk SOAR playbook automation data APIs incorporate user-supplied input into database queries without proper neutralization. For more information see Manage roles and permissions in Splunk SOAR Cloud (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) in the Splunk documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk SOARto a version that resolves this vulnerability.Fixed in 8.6.0
Event History
Frequently Asked Questions
Which users can exploit this issue?
Exploitation requires an authenticated Splunk SOAR user with the Automation Engineer role. The issue is therefore relevant where that role is assigned to users who should not be able to execute unrestricted database operations.
What level of access could successful exploitation provide?
A user with the Automation Engineer role could execute arbitrary SQL statements against the Splunk SOAR database. This could allow them to create, read, update, or delete all database data.
Which versions are affected?
Splunk SOAR versions below 8.6.0 are affected. Version 8.6.0 is not described as affected by the provided advisory information.