{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-76361","assignerOrgId":"d1c1063e-7a18-46af-9102-31f8928bc633","state":"PUBLISHED","assignerShortName":"cisco","dateReserved":"2026-08-19T12:02:03.629Z","datePublished":"2026-08-19T21:34:51.669Z","dateUpdated":"2026-08-20T16:27:34.354Z"},"containers":{"cna":{"affected":[{"product":"Splunk SOAR","vendor":"Splunk","versions":[{"version":"8.6","status":"affected","versionType":"custom","lessThan":"8.6.0"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/markdown","value":"In Splunk SOAR versions below 8.6.0, a user with the \"Administrator\" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary destinations and determine whether internal hosts and ports are reachable. The Server-Side Request Forgery (SSRF) is possible because the connectivity check REST API does not sufficiently validate the destination before Splunk SOAR connects to it. For more information see [Manage roles and permissions in Splunk SOAR (On-premises)](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) in the Splunk documentation."}],"value":"In Splunk SOAR versions below 8.6.0, a user with the \"Administrator\" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary destinations and determine whether internal hosts and ports are reachable. The Server-Side Request Forgery (SSRF) is possible because the connectivity check REST API does not sufficiently validate the destination before Splunk SOAR connects to it. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) in the Splunk documentation."}],"references":[{"url":"https://advisory.splunk.com/advisories/SVD-2026-0804"}],"title":"Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR","datePublic":"2026-08-19T00:00:00.000Z","metrics":[{"cvssV3_1":{"vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N","version":"3.1","baseScore":2.7,"baseSeverity":"LOW"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"lang":"en","type":"cwe","cweId":"CWE-918","description":"The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination."}]}],"source":{"advisory":"SVD-2026-0804"},"providerMetadata":{"orgId":"d1c1063e-7a18-46af-9102-31f8928bc633","shortName":"cisco","dateUpdated":"2026-08-19T21:34:51.669Z"},"solutions":[{"lang":"en","value":"Upgrade Splunk SOAR to 8.6.0 or higher."}],"credits":[{"lang":"en","value":"Gabriel Nitu, Splunk","type":"reporter"}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2026-76361","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2026-08-20T16:14:01.740898Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-20T16:27:34.354Z"}}]}}