CVE-2026-76361

In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary destinations and determine whether internal hosts and ports are reachable. The Server-Side Request Forgery (SSRF) is possible because the connectivity check REST API does not sufficiently validate the destination before Splunk SOAR connects to it. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) in the Splunk documentation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:*

History

No history.

Information

Published : 2026-08-19 22:17

Updated : 2026-08-21 14:45


NVD link : CVE-2026-76361

Mitre link : CVE-2026-76361

CVE.ORG link : CVE-2026-76361


JSON object : View

Products Affected

splunk

  • soar
CWE
CWE-918

Server-Side Request Forgery (SSRF)