CVE-2026-76372 PUBLISHED

Incorrect Permission Assignment through Safe Mode in Nmap Scanner for Splunk SOAR

Assigner: cisco
Reserved: 19.08.2026 Published: 19.08.2026 Updated: 19.08.2026

In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network action in a Safe Mode playbook while that action is listed as read-only, which could allow for command execution or other changes on a target system through Nmap Scripting Engine scripts. The vulnerability is possible because the Nmap Scanner connector action manifest classifies the scan network action as read-only even though the action accepts script parameters that can perform write operations. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CVSS Score: 6.6

Product Status

Vendor Splunk
Product Nmap Scanner
Versions
  • affected from 3.0 to 3.0.15 (excl.)

Workarounds

Turn off or remove the Nmap Scanner app for Splunk SOAR. For more information see Add and configure apps and assets to provide actions in Splunk SOAR in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.

Solutions

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status.

References

Problem Types

  • The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. cwe