CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-76372

mediumCVSS 6.6covered by 1 sourcefirst seen 2026-08-19
In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network action in a Safe Mode playbook while that action is listed as read-only, which could allow for command execution or other changes on a target system through Nmap Scripting Engine scripts. The vulnerability is possible because the Nmap Scanner connector action manifest classifies the scan network action as read-only even though the action accepts script parameters that can perform write operations. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.

⚡ Watch CVE-2026-76372

Get an email if CVE-2026-76372 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-76372

CVE.org record

Embed the live status

CVE-2026-76372 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-76372 status](https://www.csirts.com/badge/CVE-2026-76372)](https://www.csirts.com/cve/CVE-2026-76372)