Information Disclosure Vulnerability in Splunk SOAR
CVE-2026-76366
6.5MEDIUM
What is CVE-2026-76366?
In Splunk SOAR versions prior to 8.6.0, an authenticated user can exploit a vulnerability that allows them to apply filters on playbook runs through the REST API. This can lead to the unintentional exposure of session tokens, thereby granting access to all data associated with that user's account. The issue arises because Splunk SOAR does not adequately restrict REST API filters from exposing sensitive information that would typically be concealed in responses. For further details, refer to the Splunk advisory.
Affected Version(s)
Splunk SOAR 8.6 < 8.6.0