Executive brief
Splunk SOAR is a security orchestration platform used by enterprises to automate threat response and investigation. A vulnerability in its health monitoring endpoint allows any authenticated user without assigned roles to access system and cluster health information that should only be available to administrators. This could expose sensitive operational details about the SOAR deployment's performance, resource utilization, and cluster topology to unauthorized personnel.
Technical details
CVE-2026-76360 is an authorization bypass vulnerability (CWE-862) in Splunk SOAR's /rest/health endpoint. The vulnerability exists because the endpoint fails to verify that the caller holds a role with permission to view system health and cluster state, allowing any authenticated user to retrieve restricted telemetry. The attack requires authentication but no special privileges; the attacker simply makes a request to /rest/health and receives sensitive system information. The vulnerability affects Splunk SOAR versions below 8.6.0 and is fixed in version 8.6.0 or higher.
Affected products
- Splunk SOAR below 8.6.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Version 8.6.0 released with fix