SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-76370

MEDIUM · CVSS 4.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

In Splunk SOAR versions prior to 8.6.0, an authenticated user with limited tenant access can exploit the REST API to access the names and identifiers of tenants outside their designated role scope, due to insufficient enforcement of role-based restrictions. This vulnerability could lead to unauthorized visibility of tenant information, potentially compromising data privacy in multi-tenant environments. Organizations using affected versions of Splunk SOAR, especially those with multi-tenancy configurations, should prioritize upgrading to mitigate this risk.

CVE
CVE-2026-76370
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%

Original NVD Description

In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names and identifiers of tenants that fall outside the role scope for that user. The vulnerability is possible because Splunk SOAR does not enforce role-based tenant restrictions when it returns tenant information through the REST API in deployments with multi-tenancy turned on. For more information see REST Roles and Permissions (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/role-management-endpoints/rest-roles-and-permissions) and Configure multiple tenants on your Splunk SOAR (On-premises) instance (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/7.1.0/configure-product-settings-for-your-splunk-soar-on-premises-instance/configure-multiple-tenants-on-your-splunk-soar-on-premises-instance) in the Splunk documentation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)