SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76366

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Splunk SOAR versions prior to 8.6.0 are vulnerable to an information disclosure issue where authenticated users can exploit REST API filtering on playbook runs to retrieve session tokens, potentially compromising all accessible data. This vulnerability arises from the failure to restrict API filters from exposing hidden response values. Organizations using affected Splunk SOAR versions should prioritize patching to mitigate the risk of unauthorized data access.

CVE
CVE-2026-76366
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%

Original NVD Description

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible because Splunk SOAR does not block REST API filters from matching values that responses otherwise hide. For more information see REST Run Playbook (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/run-playbook-endpoints/rest-run-playbook) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)