Junglewise Threat Intelligence

CVE-2026-76366: Splunk SOAR REST API session token disclosure

CVE-2026-76366 · Severity: medium · CVSS 6.5 · Published 2026-08-19

Technologies: Splunk SOAR. Vendors: Splunk.

Executive brief

Splunk SOAR is a security orchestration automation and response platform used to automate security workflows. A flaw in versions below 8.6.0 allows authenticated users to recover session tokens through REST API filtering, compromising access to all data visible to that user. An attacker with valid credentials could use this to escalate privileges or expose sensitive security data.

Technical details

CVE-2026-76366 is an information disclosure vulnerability (CWE-200) in Splunk SOAR's REST API run-playbook endpoints. An authenticated user with a valid account can exploit improper REST API filtering to bypass response masking and extract session tokens that are normally hidden. The vulnerability requires a valid Splunk SOAR account and network access to the REST API; no additional privileges or special roles are needed. Successful exploitation allows an attacker to obtain session tokens that grant access to all data and functionality available to the compromised user. Splunk released a patch in version 8.6.0 addressing this issue.

Affected products

  • Splunk SOAR below 8.6.0

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 8.6.0

References

Related threats