Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
A SQL injection vulnerability in Splunk SOAR versions below 8.6.0 exists in the custom function results functionality. The application constructs database lookup queries by directly concatenating the supplied name parameter instead of using bound SQL values, allowing arbitrary SQL statements to be executed against the Splunk SOAR database.
An authenticated user holding the "Automation Engineer" role in Splunk SOAR can execute arbitrary SQL statements against the Splunk SOAR database, allowing them to read all data stored in the database and modify data to affect system integrity.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
Available - Splunk SOAR version 8.6.0 or later
Upgrade Splunk SOAR to version 8.6.0 or later. Additionally, restrict the "Automation Engineer" role to only trusted users who require custom function development capabilities. Apply principle of least privilege by limiting users with this role.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
NVD published the first details for CVE-2026-76364
A CVSS base score of 6.5 has been assigned.
Feedly found the first article mentioning CVE-2026-76364 . See article
GitHub Advisories released a security advisory .
CVE-2026-76364 | Splunk SOAR up to 8.5.x Custom Function Results sql injection
Splunk SOAR: CVSS (Max): 8.1
SVD-2026-0804: Security Hardening Release for Splunk SOAR - August 2026
Collect, analyze, and vulnerability reports faster using AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
