Missing Authorization in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76360

 

Missing Authorization in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76360

Published: August 20, 2026


Vulnerability identifier: #VU144491
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76360
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the /rest/health endpoint when handling requests for system health and cluster state. A remote user can query the endpoint to disclose sensitive information.

The exposed data includes system and cluster telemetry.


Affected software

Splunk Security Orchestration, Automation and Response (SOAR)

How to mitigate CVE-2026-76360

Install security update from vendor's website.

Splunk Security Orchestration, Automation and Response (SOAR) - update to 8.6.0

External References

Related Security Bulletins