Sceawere
Vulnerability Detail
CVE-2026-76356UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Splunk SOAR Automation Broker IP Spoofing RCE
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 17h ago
- Vendor
- Splunk
- Product
- Splunk SOAR
- Attack Type
- This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In Splunk SOAR versions below 8.6.0, an unauthenticated user could spoof the source IP address in a crafted request to an Automation Broker notification endpoint and execute arbitrary code on the Splunk SOAR host. The vulnerability is possible because the Splunk SOAR Automation Broker trusts a client-supplied source IP address header as proof that the request originates from the local system. Successful exploitation can expose all relevant data, affect system integrity, and disrupt service availability. For more information see About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-08-19T22:17:20.727Z",
"pubdate": "2026-08-19T22:17:20.727Z",
"executiveSummary": "An unauthenticated remote code execution vulnerability exists in Splunk SOAR versions below 8.6.0 involving the Automation Broker notification endpoint.\nThe vulnerability stems from improper input validation and trust handling, specifically where the Splunk SOAR Automation Broker relies entirely on a client-supplied HTTP header to determine the source IP address.\nBy spoofing this source IP address header in a specially crafted HTTP request, an unauthenticated attacker can deceive the application into treating external traffic as originating from the local system.\nSuccessful exploitation of this flaw allows malicious actors to execute arbitrary code with the privileges of the Splunk SOAR host, leading to complete compromise of system integrity, exposure of sensitive data, and severe disruption of service availability.\nThe attack requires network access to the Automation Broker notification endpoint without requiring prior authentication or valid user credentials.\nOrganizations utilizing affected Splunk SOAR deployments face high risk until proper remediation is applied.",
"technicalDetails": "The root cause of the vulnerability resides in the trust boundary enforcement within the Splunk SOAR Automation Broker notification endpoint across versions below 8.6.0.\nThe affected component insecurely parses and relies upon client-supplied HTTP headers—specifically headers intended to convey source IP address information—as authoritative proof that incoming requests originate from localhost or trusted internal components.\nBecause the application fails to validate the true transport-layer socket connection against the declared header value, it suffers from a classic IP spoofing vulnerability at the application layer.\nThe attack flow begins when an unauthenticated attacker crafts a malicious HTTP request targeting the Automation Broker notification endpoint over the network.\nWithin this crafted request, the attacker injects a manipulated source IP address header designed to mimic a local system origin.\nUpon receiving the request, the Automation Broker processes the header, incorrectly assumes the request is locally generated, and bypasses intended security controls or authentication checks designed to restrict privileged operations.\nBy leveraging this trust misdirection, the attacker delivers a malicious payload capable of executing arbitrary code on the underlying Splunk SOAR host operating system.\nThe authentication requirement for this attack is completely absent, allowing unauthenticated remote threat actors to trigger the execution path.\nThe execution privileges correspond directly to the security context under which the vulnerable Automation Broker service runs, typically leading to full system compromise.\nPost-exploitation impact includes unauthorized data exfiltration, modification of system configurations, complete loss of confidentiality and integrity, and operational denial of service."
}