Description
In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible because Splunk SOAR does not block REST API filters from matching values that responses otherwise hide. For more information see REST Run Playbook (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/run-playbook-endpoints/rest-run-playbook) in the Splunk documentation.
Published: 2026-08-19
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because Splunk SOAR leaks session tokens in the responses of the REST API run‑playbook endpoint when filters are applied to playbook runs. An attacker who possesses a valid Splunk SOAR account can use the API to filter results and obtain session tokens that grant access to all data available to that user. This flaw results in a classic information‑disclosure weakness (CWE-200) and undermines the confidentiality of the entire dataset accessible to the compromised account.

Affected Systems

Splunk SOAR deployments with versions older than 8.6.0 are vulnerable. The affected product is Splunk SOAR from vendor Splunk. Any release below 8.6.0 exposes the session tokens via the REST API filtering feature.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity mainly due to the authentication requirement. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated Splunk SOAR user who can call the REST run‑playbook endpoint; with such access the attacker can retrieve session tokens, compromising all data available to that account. The attack vector is therefore limited to authorized users who have API privileges, but still poses a significant risk to confidentiality within the environment.

Generated by OpenCVE AI on August 20, 2026 at 10:45 UTC.

Remediation

Vendor Solution

Upgrade Splunk SOAR to 8.6.0 or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk SOAR to 8.6.0 or newer to eliminate the API behavior that exposes session tokens.
  • Audit API access logs and enforce that only privileged accounts can use playbook run filtering.
  • Apply least‑privilege role configuration to restrict users’ ability to retrieve session tokens via the API.

Generated by OpenCVE AI on August 20, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk soar
CPEs cpe:2.3:a:splunk:soar:*:*:*:*:cloud:*:*:*
cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:*
Vendors & Products Splunk soar

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Vendors & Products Splunk
Splunk splunk

Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible because Splunk SOAR does not block REST API filters from matching values that responses otherwise hide. For more information see REST Run Playbook (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/run-playbook-endpoints/rest-run-playbook) in the Splunk documentation.
Title Information Disclosure through the REST API in Splunk SOAR
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:33.568Z

Reserved: 2026-08-19T12:02:03.629Z

Link: CVE-2026-76366

cve-icon Vulnrichment

Updated: 2026-08-20T16:22:37.817Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:22.023

Modified: 2026-08-21T14:54:44.580

Link: CVE-2026-76366

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:38Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor