PatchSiren cyber security CVE debrief
CVE-2026-76367 Splunk CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:22.153Z and has not been modified since then. Splunk SOAR versions below 8.6.0 contain a Cross-Site Scripting (XSS) vulnerability. An Incident Commander role user can store JavaScript in a note, potentially running it in another user's browser when they open the note. However, exploitation requires phishing the affected user. To mitigate, review and update Splunk SOAR to version 8.6.0 or higher, restrict Incident Commander role usage to trusted users, and implement additional phishing protection measures.
- Vendor
- Splunk
- Product
- Splunk SOAR
- CVSS
- MEDIUM 4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-08-21
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-08-21
Who should care
Splunk SOAR administrators, Incident Commander role users, and users who interact with notes in Splunk SOAR should be aware of this vulnerability and take necessary precautions. Administrators should review and update Splunk SOAR to version 8.6.0 or higher and restrict Incident Commander role usage to trusted users. Users should be cautious when opening notes from untrusted sources and report any suspicious activity to the appropriate teams. Additionally, implementing phishing protection measures can help prevent exploitation of this vulnerability. Security teams should monitor user activity and note content for potential XSS attempts and implement compensating controls for exposed systems while remediation is scheduled and verified. Asset inventory and rollback/change windows should also be reviewed to ensure proper mitigation of this vulnerability. Source tracking and monitoring can help detect and respond to potential attacks. It is recommended to review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Asset inventory and rollback/change windows should be reviewed to ensure proper mitigation of this vulnerability. Source tracking and monitoring can help detect and respond to potential attacks. It is recommended to review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Check relevant monitoring, detection, and logs for exposed assets that need extra review. Track exceptions, retest remediated assets, and close the item only after evidence is
Technical summary
A Cross-Site Scripting (XSS) vulnerability exists in Splunk SOAR versions below 8.6.0. An user with the Incident Commander role can store JavaScript in a note, which can be executed in the browser of another user when they open the note. The vulnerability requires the attacker to phish the affected user to initiate a request within their browser. This issue arises because Splunk SOAR can treat existing note content as Hypertext Markup Language (HTML) without sanitizing that content when the note format changes.
Defensive priority
Medium-priority defensive review recommended due to potential for user-targeted attacks.
Recommended defensive actions
- Review and update Splunk SOAR to version 8.6.0 or higher.
- Restrict Incident Commander role usage to trusted users.
- Monitor user activity and note content for potential XSS attempts.
- Implement additional phishing protection measures for users.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
Evidence from official sources indicates a Cross-Site Scripting (XSS) vulnerability exists in Splunk SOAR versions below 8.6.0. An Incident Commander role user could store JavaScript in a note, potentially running it in another user's browser. However, exploitation requires phishing the affected user. Additional review of user interactions and note content is recommended to detect potential XSS attempts.
Official resources
-
CVE-2026-76367 CVE record
CVE.org
-
CVE-2026-76367 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T22:17:22.153Z and has not been modified since then.