Data Exposure Vulnerability in Splunk SOAR by Splunk
CVE-2026-76370

4.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76370?

In certain versions of Splunk SOAR, a vulnerability exists that allows authenticated users with restricted tenant access to exploit the REST API. This flaw enables them to retrieve names and identifiers of tenants that should be inaccessible based on their role. The oversight arises from the lack of enforcement of role-based tenant restrictions in environments with multi-tenancy enabled, potentially exposing sensitive tenant information. It's crucial for organizations using impacted versions to assess their configurations and apply necessary mitigations to fortify their systems against unauthorized data access.

Affected Version(s)

Splunk SOAR 8.6 < 8.6.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.