Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status.
Workaround
Turn off or remove the FireAMP app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-cloud) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.
| Link | Providers |
|---|---|
| https://advisory.splunk.com/advisories/SVD-2026-0806 |
|
Wed, 19 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the FireAMP connector action manifest classifies the add listitem action as read-only even though the action updates file lists. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation. | |
| Title | Incorrect Permission Assignment through Safe Mode in FireAMP for Splunk SOAR | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: cisco
Published:
Updated: 2026-08-19T21:34:57.646Z
Reserved: 2026-08-19T12:02:03.630Z
Link: CVE-2026-76371
No data.
No data.
No data.
OpenCVE Enrichment
No data.