Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/splunk/splunk-soar

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-76370 is a medium-severity vulnerability in Splunk SOAR versions prior to 8.6.0. It allows an authenticated user with restricted tenant access to bypass role-based tenant restrictions via the REST API, enabling them to view tenant names and identifiers outside their authorized scope in multi-tenant deployments. This occurs because the software does not correctly enforce authorization checks when returning tenant information through the REST API.

Join the discussion

CVE-2026-76369 is a low-severity path traversal vulnerability in Splunk SOAR versions prior to 8.6.0. It allows a user with the OnPrem Broker role to write files outside the intended Automation Broker log directory by exploiting insufficient sanitization of crafted filenames during log uploads.

Join the discussion

CVE-2026-76368 is a low-severity vulnerability in Splunk SOAR versions prior to 8.6.0 where users with the playbooks:view permission can view metadata about playbook repositories they are not authorized to access. This occurs because the Playbook History feature does not verify repository permissions before returning playbook revision metadata.

Join the discussion

CVE-2026-76367 is a stored Cross-Site Scripting (XSS) vulnerability in Splunk SOAR versions below 8.6.0. It allows a user with the "Incident Commander" role to store JavaScript in a note, which executes in the browser of another user viewing that note. The vulnerability arises because note content can be treated as HTML without proper sanitization when the note format changes. Exploitation requires tricking the victim user into initiating a request in their browser. This vulnerability has a medium severity rating and a CVSS score of 4.0.

Join the discussion

CVE-2026-76366 is a medium severity vulnerability in Splunk SOAR versions before 8.6.0. It allows a user with a valid account to exploit REST API filtering on playbook runs to retrieve session tokens. These tokens can expose all data accessible to the affected user. The issue arises because the REST API does not properly block filters from matching values that should be hidden in responses. This vulnerability affects versions prior to 8.6.0.

Join the discussion

CVE-2026-76365 is a SQL injection vulnerability in Splunk SOAR versions prior to 8.6.0. A user with the Automation Engineer role can execute arbitrary SQL commands against the Splunk SOAR database via custom list retrieval in playbooks. This allows unauthorized create, read, update, and delete operations on database data. The vulnerability arises because the software improperly constructs SQL queries using externally supplied list names without proper parameterization.

Join the discussion

CVE-2026-76364 is a SQL injection vulnerability in Splunk SOAR versions prior to 8.6.0. A user with the "Automation Engineer" role can execute arbitrary SQL queries against the Splunk SOAR database via custom function results. This occurs because the software constructs SQL commands using externally influenced input without proper neutralization, allowing unauthorized reading of sensitive data and impacting system integrity.

Join the discussion

CVE-2026-76363 is a vulnerability in Splunk SOAR versions prior to 8.6.0 where users with the Automation Engineer role can execute arbitrary SQL queries against the application's database. This occurs because user input is not properly neutralized in database queries within playbook automation data APIs, allowing unauthorized creation, reading, updating, or deletion of data. The vulnerability has a medium severity rating with a CVSS score of 6.5.

Join the discussion

CVE-2026-76360 is a vulnerability in Splunk SOAR versions prior to 8.6.0 where an authenticated user without an assigned role can access the /rest/health endpoint. This endpoint exposes system and cluster telemetry information that should be restricted to administrative or support users. The issue arises from a missing authorization check, allowing unauthorized access to sensitive system health data.

Join the discussion

CVE-2026-76359 is a path traversal vulnerability in Splunk SOAR versions prior to 8.6.0. It allows a user with Administrator privileges to exploit the Universal Forwarder installer's archive extraction process to write files outside the intended installation directory. This occurs because the extraction workflow does not properly verify that archive members remain within the designated destination directory. The vulnerability can lead to unauthorized file writes, impacting system integrity and availability.

Join the discussion

Showing 1 to 10 of 14 results

Filters:Package: pkg:github/splunk/splunk-soar
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses