Junglewise Threat Intelligence

CVE-2026-76360: Splunk SOAR missing authorization in health REST API

CVE-2026-76360 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Technologies: Splunk SOAR. Vendors: Splunk.

Executive brief

Splunk SOAR is a security orchestration platform used by enterprises to automate threat response and investigation. A vulnerability in its health monitoring endpoint allows any authenticated user without assigned roles to access system and cluster health information that should only be available to administrators. This could expose sensitive operational details about the SOAR deployment's performance, resource utilization, and cluster topology to unauthorized personnel.

Technical details

CVE-2026-76360 is an authorization bypass vulnerability (CWE-862) in Splunk SOAR's /rest/health endpoint. The vulnerability exists because the endpoint fails to verify that the caller holds a role with permission to view system health and cluster state, allowing any authenticated user to retrieve restricted telemetry. The attack requires authentication but no special privileges; the attacker simply makes a request to /rest/health and receives sensitive system information. The vulnerability affects Splunk SOAR versions below 8.6.0 and is fixed in version 8.6.0 or higher.

Affected products

  • Splunk SOAR below 8.6.0

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Version 8.6.0 released with fix

References

Related threats