CVE-2026-76371
Received Received - Intake

FireAMP Connector Playbook Add Listitem Action Privilege Escalation

Vulnerability report for CVE-2026-76371, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In FireAMP versions below 2.1.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the add listitem action in a Safe Mode playbook while that action is listed as read-only, which could allow for unauthorized changes to file lists. The vulnerability is possible because the FireAMP connector action manifest classifies the add listitem action as read-only even though the action updates file lists. For more information see Manage settings for a playbook in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-cloud/build-playbooks/manage-playbooks-and-playbook-settings/manage-settings-for-a-playbook-in-splunk-soar-cloud) in the Splunk documentation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
cisco fireamp to 2.1.15 (exc)
splunk soar *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In FireAMP versions below 2.1.15, a user with permissions to edit or run playbooks in Splunk SOAR could exploit a flaw in Safe Mode playbooks. The 'add listitem' action, which should be read-only, incorrectly allows unauthorized changes to file lists due to a misclassification in the FireAMP connector action manifest.

Detection Guidance

To detect this vulnerability, check FireAMP versions below 2.1.15 and Splunk SOAR playbooks with Safe Mode enabled. Review playbook actions for unauthorized 'add listitem' usage in file lists. No specific commands are provided in the context.

Impact Analysis

This vulnerability could allow unauthorized modifications to file lists, potentially leading to unintended changes in security policies or configurations. If exploited, it might disrupt operations or bypass intended restrictions in Splunk SOAR.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or similar standards. It involves unauthorized changes to file lists in Splunk SOAR due to a misclassified action in FireAMP versions below 2.1.15. No evidence suggests it impacts data protection or privacy requirements under these regulations.

Mitigation Strategies

Upgrade FireAMP to version 2.1.15 or later to address the misclassification of the add listitem action in Safe Mode playbooks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76371. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart