Description
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing authorization check, where the endpoint does not verify that the caller holds a role permitted to view system health and cluster state. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) and Monitor the health of your Splunk SOAR (On-premises) system (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-system-health-and-performance/monitor-the-health-of-your-splunk-soar-on-premises-system) in the Splunk documentation.
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Splunk SOAR releases before 8.6.0, the /rest/health API endpoint lacks an authorization check. An authenticated user who has no role assignment can call the endpoint and receive system and cluster telemetry that should only be available to administrators or support staff. The flaw can expose configuration details, version information, and cluster state, thereby compromising the confidentiality of the platform’s operational data.

Affected Systems

Affected vendors include Splunk; the product is Splunk SOAR. All versions earlier than 8.6.0 contain the vulnerability. No specific minor releases are listed, but any installation using a pre‑8.6.0 build is potentially impacted.

Risk and Exploitability

The CVSS score is 4.3, indicating a moderate severity for an unauthorized data exposure. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector requires authentication but does not require privileged roles; therefore, any user account that can authenticate without being assigned a role could leverage the flaw to obtain sensitive system telemetry.

Generated by OpenCVE AI on August 20, 2026 at 10:08 UTC.

Remediation

Vendor Solution

Upgrade Splunk SOAR to 8.6.0 or higher.


OpenCVE Recommended Actions

  • Update Splunk SOAR to version 8.6.0 or later to apply the missing authorization fix
  • Review all user accounts and assign a role to each; remove any accounts that exist without a role assignment
  • If possible, disable or restrict network access to the /rest/health endpoint for non‑trusted networks
  • Verify that role checks are enforced for the health endpoint by testing with a low‑privileged user after applying the patch

Generated by OpenCVE AI on August 20, 2026 at 10:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk soar
CPEs cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:*
Vendors & Products Splunk soar

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Vendors & Products Splunk
Splunk splunk

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could use the /rest/health endpoint to gather system and cluster telemetry that should be restricted to administrative or support users. The vulnerability is a missing authorization check, where the endpoint does not verify that the caller holds a role permitted to view system health and cluster state. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) and Monitor the health of your Splunk SOAR (On-premises) system (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-system-health-and-performance/monitor-the-health-of-your-splunk-soar-on-premises-system) in the Splunk documentation.
Title Information Disclosure through Missing Authorization in the Health REST API in Splunk SOAR
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:34.503Z

Reserved: 2026-08-19T12:02:03.629Z

Link: CVE-2026-76360

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:21.267

Modified: 2026-08-21T14:45:01.643

Link: CVE-2026-76360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:48Z

Weaknesses