Junglewise Threat Intelligence

CVE-2026-76365: Splunk SOAR SQL injection through custom lists

CVE-2026-76365 · Severity: medium · CVSS 6.5 · Published 2026-08-19

Technologies: Splunk SOAR. Vendors: Splunk.

Executive brief

Splunk SOAR is a security automation and orchestration platform used by security teams to automate incident response and threat management. Users with the "Automation Engineer" role can exploit a SQL injection flaw in custom list retrieval to run arbitrary database commands against the SOAR platform, potentially reading, modifying, or deleting sensitive security data and investigation records.

Technical details

This is a SQL injection vulnerability (CWE-74) in Splunk SOAR versions below 8.6.0 affecting the custom list retrieval functionality. The root cause is that the application constructs SQL queries by directly concatenating user-supplied list names instead of using parameterized queries or bound values. An authenticated user holding the "Automation Engineer" role can exploit this through a playbook's custom list comparison feature. The attack requires authentication and the specific role assignment, but no additional user interaction. Successful exploitation allows full CRUD operations against the SOAR database, exposing or modifying all stored data. The fix is to upgrade to version 8.6.0 or higher.

Affected products

  • Splunk SOAR below 8.6.0

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fix available in version 8.6.0

References

Related threats