CVE Tools

Splunk Soar

16 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Splunk Soar, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.

Splunk Soar CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Splunk Soar CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-061
2026-070
2026-0815
2026-090

Severity

How the 16 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High319%
  • Medium1063%
  • Low319%

Latest CVEs

The 15 most recently published vulnerabilities affecting Splunk Soar.

  1. CVE-2026-76370Information Disclosure through the REST API in Splunk SOAR4.3
  2. CVE-2026-76369Path Traversal through Automation Broker in Splunk SOAR2.7
  3. CVE-2026-76368Missing Authorization through Playbooks in Splunk SOAR2.7
  4. CVE-2026-76367Stored Cross-Site Scripting (XSS) through Notes in Splunk SOAR4.0
  5. CVE-2026-76366Information Disclosure through the REST API in Splunk SOAR6.5
  6. CVE-2026-76365Structured Query Language (SQL) Injection through Custom Lists in Splunk SOAR6.5
  7. CVE-2026-76364Structured Query Language (SQL) Injection through Custom Function Results in Splunk SOAR6.5
  8. CVE-2026-76362Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR7.4
  9. CVE-2026-76363Structured Query Language Injection through the REST API in Splunk SOAR6.5
  10. CVE-2026-76360Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR4.3
  11. CVE-2026-76361Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR2.7
  12. CVE-2026-76359Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR6.5
  13. CVE-2026-76358Path Traversal through App Installation Tar Extraction in Splunk SOAR6.5
  14. CVE-2026-76357Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR7.6
  15. CVE-2026-76356Authentication Bypass through IP Address Spoofing in the Automation Broker in Splunk SOAR8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store