Incorrect authorization in Splunk Security Orchestration, Automation and Response (SOAR) - CVE-2026-76370
Published: August 20, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper authorization in the REST API when returning tenant information without enforcing role-based tenant restrictions. A remote user can query the REST API to disclose sensitive information.
Only deployments with multi-tenancy turned on are vulnerable.