Executive brief
Splunk SOAR is a security orchestration automation and response platform used to automate security workflows. A flaw in versions below 8.6.0 allows authenticated users to recover session tokens through REST API filtering, compromising access to all data visible to that user. An attacker with valid credentials could use this to escalate privileges or expose sensitive security data.
Technical details
CVE-2026-76366 is an information disclosure vulnerability (CWE-200) in Splunk SOAR's REST API run-playbook endpoints. An authenticated user with a valid account can exploit improper REST API filtering to bypass response masking and extract session tokens that are normally hidden. The vulnerability requires a valid Splunk SOAR account and network access to the REST API; no additional privileges or special roles are needed. Successful exploitation allows an attacker to obtain session tokens that grant access to all data and functionality available to the compromised user. Splunk released a patch in version 8.6.0 addressing this issue.
Affected products
- Splunk SOAR below 8.6.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in version 8.6.0