Data Exposure Vulnerability in Splunk SOAR by Splunk
CVE-2026-76370
4.3MEDIUM
What is CVE-2026-76370?
In certain versions of Splunk SOAR, a vulnerability exists that allows authenticated users with restricted tenant access to exploit the REST API. This flaw enables them to retrieve names and identifiers of tenants that should be inaccessible based on their role. The oversight arises from the lack of enforcement of role-based tenant restrictions in environments with multi-tenancy enabled, potentially exposing sensitive tenant information. It's crucial for organizations using impacted versions to assess their configurations and apply necessary mitigations to fortify their systems against unauthorized data access.
Affected Version(s)
Splunk SOAR 8.6 < 8.6.0