Impact
An authenticated user with restricted tenant permissions can use the REST API to retrieve the names and identifiers of tenants that lie outside the user’s role scope. The vulnerability arises because Splunk SOAR does not enforce role‑based tenant restrictions when it returns tenant information in multi‑tenant deployments. This flaw results in the exposure of sensitive tenant metadata such as names and IDs, thereby violating confidentiality.
Affected Systems
Splunk SOAR deployments running versions earlier than 8.6.0 are affected when multi‑tenancy is enabled. Users of these versions should ensure they are not using older versions or have applied the appropriate upgrade.
Risk and Exploitability
The CVSS base score of 4.3 indicates a moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. Attackers need to be authenticated and have a restricted tenant role; they can simply call the REST API to obtain sensitive identifiers of other tenants. The risk is confined to confidentiality breach rather than privilege escalation or denial of service.
OpenCVE Enrichment