Information disclosure in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76366
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to information disclosure in REST API filtering on playbook runs when matching filter values in hidden response fields. A remote user can use crafted REST API filters to disclose sensitive information.
The issue can expose session tokens.