Junglewise Threat Intelligence

CVE-2026-76362: Splunk SOAR improper certificate validation in CyberArk integration

CVE-2026-76362 · Severity: high · CVSS 7.4 · Published 2026-08-19

Technologies: Splunk SOAR. Vendors: Splunk.

Executive brief

Splunk SOAR is a security orchestration platform used to automate incident response workflows. An unauthenticated attacker with network access between SOAR and its configured CyberArk credential vault could intercept and modify all credentials and sensitive data exchanged between them, because the CyberArk REST client does not verify server certificates by default. This could lead to credential theft, unauthorized access to protected systems, and compromise of the entire credential management infrastructure.

Technical details

This vulnerability is an improper certificate validation flaw (CWE-295) in Splunk SOAR's CyberArk Vault Privileged Access Manager (PAM) REST client integration. The CyberArk REST client does not verify server certificates by default, making it vulnerable to man-in-the-middle (MITM) attacks. An unauthenticated attacker with network-path interception capability between Splunk SOAR and the configured CyberArk REST server can observe, intercept, and modify all credential data exchanged through that credential manager. The attack requires the attacker to be on the network path between SOAR and the CyberArk server. Splunk released a fix in version 8.6.0; affected versions are below 8.6.0. Additional remediation steps beyond upgrading are required.

Affected products

  • Splunk SOAR below 8.6.0

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fix released in Splunk SOAR 8.6.0

References

Related threats