CVE-2026-76366

Information Disclosure through the REST API in Splunk SOAR

Severity
Medium 6.5
CVSS 3.1
Exploited
Not listed
EPSS
0.003
21.3th percentile
Discovered by
Not disclosed
Published
Aug 19, 2026
Assigned by cisco

Description

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible because Splunk SOAR does not block REST API filters from matching values that responses otherwise hide. For more information see REST Run Playbook (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/run-playbook-endpoints/rest-run-playbook) in the Splunk documentation.

Weakness: CWE-200

Affected products

Vendor Product Category Matched by
Cisco Splunk SOAR SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Splunk · Splunk SOAR

Vendor remediation

Upgrade Splunk SOAR to 8.6.0 or higher.

Something wrong here?