Improper Certificate Validation in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76362
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to access or modify sensitive data exchanged through the credential manager.
The vulnerability exists due to improper certificate validation in the CyberArk REST client when communicating with a configured CyberArk REST server. A remote attacker can intercept or alter network traffic to access or modify sensitive data exchanged through the credential manager.
Exploitation requires network-path interception capability between Splunk SOAR and the configured CyberArk REST server.