Description
In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names and identifiers of tenants that fall outside the role scope for that user. The vulnerability is possible because Splunk SOAR does not enforce role-based tenant restrictions when it returns tenant information through the REST API in deployments with multi-tenancy turned on. For more information see REST Roles and Permissions (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/role-management-endpoints/rest-roles-and-permissions) and Configure multiple tenants on your Splunk SOAR (On-premises) instance (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/7.1.0/configure-product-settings-for-your-splunk-soar-on-premises-instance/configure-multiple-tenants-on-your-splunk-soar-on-premises-instance) in the Splunk documentation.
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated user with restricted tenant permissions can use the REST API to retrieve the names and identifiers of tenants that lie outside the user’s role scope. The vulnerability arises because Splunk SOAR does not enforce role‑based tenant restrictions when it returns tenant information in multi‑tenant deployments. This flaw results in the exposure of sensitive tenant metadata such as names and IDs, thereby violating confidentiality.

Affected Systems

Splunk SOAR deployments running versions earlier than 8.6.0 are affected when multi‑tenancy is enabled. Users of these versions should ensure they are not using older versions or have applied the appropriate upgrade.

Risk and Exploitability

The CVSS base score of 4.3 indicates a moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. Attackers need to be authenticated and have a restricted tenant role; they can simply call the REST API to obtain sensitive identifiers of other tenants. The risk is confined to confidentiality breach rather than privilege escalation or denial of service.

Generated by OpenCVE AI on August 20, 2026 at 10:56 UTC.

Remediation

Vendor Solution

Upgrade Splunk SOAR to 8.6.0 or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk SOAR to version 8.6.0 or newer.
  • Restrict or remove users’ tenant permissions that allow access to the vulnerable REST endpoints until the patch is applied.
  • Verify multi‑tenancy configuration follows vendor guidelines to ensure role‑based tenant restrictions are enforced.

Generated by OpenCVE AI on August 20, 2026 at 10:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk soar
CPEs cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:*
Vendors & Products Splunk soar

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Vendors & Products Splunk
Splunk splunk

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access could use the Representational State Transfer (REST) API to view the names and identifiers of tenants that fall outside the role scope for that user. The vulnerability is possible because Splunk SOAR does not enforce role-based tenant restrictions when it returns tenant information through the REST API in deployments with multi-tenancy turned on. For more information see REST Roles and Permissions (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/role-management-endpoints/rest-roles-and-permissions) and Configure multiple tenants on your Splunk SOAR (On-premises) instance (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/7.1.0/configure-product-settings-for-your-splunk-soar-on-premises-instance/configure-multiple-tenants-on-your-splunk-soar-on-premises-instance) in the Splunk documentation.
Title Information Disclosure through the REST API in Splunk SOAR
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:33.108Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76370

cve-icon Vulnrichment

Updated: 2026-08-20T16:22:22.536Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:22.733

Modified: 2026-08-21T14:46:44.140

Link: CVE-2026-76370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:32Z

Weaknesses