Junglewise Threat Intelligence

CVE-2026-76364: Splunk SOAR SQL injection through custom function results

CVE-2026-76364 · Severity: medium · CVSS 6.5 · Published 2026-08-19

Technologies: Splunk SOAR. Vendors: Splunk.

Executive brief

Splunk SOAR is a security orchestration platform that automates incident response workflows. In versions before 8.6.0, users with the "Automation Engineer" role could inject SQL commands to read or modify all data stored in the SOAR database, exposing sensitive incident data and potentially compromising the integrity of security operations.

Technical details

A SQL injection vulnerability (CWE-89) exists in Splunk SOAR's custom function results handler where user-supplied database lookup names are concatenated directly into SQL queries instead of using parameterized/bound statements. An authenticated attacker with the Automation Engineer role can exploit this by crafting malicious input through custom function results to execute arbitrary SQL statements. The vulnerability requires authentication and the specific Automation Engineer role, but allows complete database access including reading all data stored in SOAR. A fix is available in version 8.6.0 and higher.

Affected products

  • Splunk SOAR below 8.6.0

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 8.6.0

References

Related threats