Information disclosure in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76366

 

Information disclosure in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76366

Published: August 20, 2026


Vulnerability identifier: #VU144497
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-76366
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to information disclosure in REST API filtering on playbook runs when matching filter values in hidden response fields. A remote user can use crafted REST API filters to disclose sensitive information.

The issue can expose session tokens.


Affected software

Splunk Security Orchestration, Automation and Response (SOAR)

How to mitigate CVE-2026-76366

Install security update from vendor's website.

Splunk Security Orchestration, Automation and Response (SOAR) - update to 8.6.0

External References

Related Security Bulletins