PT-2026-78789 · Splunk+1 · Splunk Soar+1

CVE-2026-76362

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Splunk SOAR versions prior to 8.6.0
Description An unauthenticated user with the ability to intercept network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server can access or modify data exchanged via the credential manager. This occurs because the CyberArk REST client does not verify server certificates by default, allowing an attacker with network-path interception capabilities to compromise the communication.
Recommendations Update to version 8.6.0 or later.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76362

Affected Products

Cyberark Rest Server
Splunk Soar