Access Control Flaw in Splunk SOAR Affects User Permissions
CVE-2026-76368
2.7LOW
What is CVE-2026-76368?
In certain versions of Splunk SOAR, users with insufficient permissions can inadvertently access metadata related to playbooks they should not have visibility into. This issue arises because the system fails to enforce repository permissions, allowing unauthorized users to view sensitive playbook revision information. Proper management of roles and permissions is crucial to mitigating this exposure.
Affected Version(s)
Splunk SOAR 8.6 < 8.6.0