Executive brief
Splunk SOAR is a security orchestration and automation platform used to automate incident response workflows. An Administrator account could exploit a connectivity check feature to initiate outbound connections to internal systems and network ports, allowing reconnaissance of internal network topology and port accessibility.
Technical details
CVE-2026-76361 is a Server-Side Request Forgery (SSRF) vulnerability in Splunk SOAR versions below 8.6.0. The /rest/support/connectivity/.../check_connectivity REST API endpoint does not sufficiently validate destination targets before initiating outbound connections. An Administrator-role user can exploit this to make the SOAR instance connect to arbitrary internal and external destinations, determining reachability of internal hosts and ports. The vulnerability requires Administrator privileges and network access to the REST API. Patches are available in Splunk SOAR 8.6.0 and later.
Affected products
- Splunk SOAR below 8.6.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fix available in Splunk SOAR 8.6.0