Description
In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server could access or modify all relevant data exchanged through that credential manager. The vulnerability is possible because the CyberArk REST client does not verify server certificates by default. The attack requires the attacker to have network-path interception capability between Splunk SOAR and the configured CyberArk REST server. For more information see Manage your organization's credentials with a password vault (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/configure-administration-settings-in-splunk-soar-cloud/manage-your-organizations-credentials-with-a-password-vault) in the Splunk documentation.
Published: 2026-08-19
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker who can intercept or tamper with traffic between a Splunk SOAR instance and its configured CyberArk REST server can read or alter the credential data exchanged by the credential manager. The root cause is that the CyberArk REST client does not verify server certificates by default, allowing the attacker to capture or modify sensitive authentication material. This vulnerability enables an attacker to obtain, modify, or delete credential information that Splunk SOAR uses to authenticate with other systems, resulting in possible credential theft or service disruption.

Affected Systems

Splunk SOAR software versions earlier than 8.6.0 are affected. The vulnerability applies to any configuration that uses a CyberArk REST credential manager with the default (certificate verification disabled) setting.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, suggesting it may currently have low exploitation prevalence but a still significant risk if an attacker gains network visibility. The attack requires interception of the network path between Splunk SOAR and the CyberArk server, which is realistic for attackers who can compromise network devices or use a man‑in‑the‑middle position. The CNA solution recommends upgrading to version 8.6.0 or later to enforce certificate validation, thereby mitigating the risk.

Generated by OpenCVE AI on August 20, 2026 at 10:06 UTC.

Remediation

Vendor Solution

Upgrade Splunk SOAR to 8.6.0 or higher. For existing CyberArk REST credential-manager configurations, turn on Verify server certificate after upgrading.


OpenCVE Recommended Actions

  • Upgrade Splunk SOAR to 8.6.0 or later
  • Enable the Verify server certificate option in the CyberArk REST credential‑manager configuration after upgrading
  • Secure the network path between Splunk SOAR and the CyberArk REST server to prevent traffic interception

Generated by OpenCVE AI on August 20, 2026 at 10:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Splunk soar
CPEs cpe:2.3:a:splunk:soar:*:*:*:*:cloud:*:*:*
cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:*
Vendors & Products Splunk soar

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Vendors & Products Splunk
Splunk splunk

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server could access or modify all relevant data exchanged through that credential manager. The vulnerability is possible because the CyberArk REST client does not verify server certificates by default. The attack requires the attacker to have network-path interception capability between Splunk SOAR and the configured CyberArk REST server. For more information see Manage your organization's credentials with a password vault (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/configure-administration-settings-in-splunk-soar-cloud/manage-your-organizations-credentials-with-a-password-vault) in the Splunk documentation.
Title Improper Certificate Validation through CyberArk Vault Privileged Access Manager in Splunk SOAR
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-21T03:56:04.383Z

Reserved: 2026-08-19T12:02:03.629Z

Link: CVE-2026-76362

cve-icon Vulnrichment

Updated: 2026-08-20T16:22:58.308Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:21.533

Modified: 2026-08-21T14:55:01.917

Link: CVE-2026-76362

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:44Z

Weaknesses
  • CWE-295

    Improper Certificate Validation