SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-76371

LOW · CVSS 2.7 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

In FireAMP versions prior to 2.1.15, users with permissions to edit, create, or run playbooks in Splunk SOAR can exploit a misclassification of the add listitem action as read-only, allowing unauthorized modifications to file lists. This vulnerability poses a risk of unauthorized changes that could compromise data integrity within playbooks. Organizations utilizing affected versions of FireAMP should prioritize remediation to mitigate potential security risks associated with unauthorized access and modifications.

CVE
CVE-2026-76371
Severity
LOW
CVSS
2.7
EPSS
0.21%

Original NVD Description

In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the FireAMP connector action manifest classifies the add listitem action as read-only even though the action updates file lists. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.