CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-27959

highcovered by 3 sourcesfirst seen 2026-07-21
Ein Angreifer kann mehrere Schwachstellen in Splunk SOAR ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um einen Cross-Site Scripting Angriff durchzuführen, und um beliebigen Programmcode auszuführen.

CSIRTS triage

What
Multiple vulnerabilities in Splunk SOAR enable attackers to bypass security, disclose information, manipulate files, perform SQL injection and cross-site scripting, and execute arbitrary code.
Who is affected
All Splunk SOAR deployments are affected.
Urgency
High severity; multiple critical attack classes including RCE and auth bypass warrant immediate action.
Action
Update Splunk SOAR to the latest patched version immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-27959

Get an email if CVE-2026-27959 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-27959

CVE.org record

Embed the live status

CVE-2026-27959 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-27959 status](https://www.csirts.com/badge/CVE-2026-27959)](https://www.csirts.com/cve/CVE-2026-27959)