PT-2026-78797 · Splunk · Splunk Soar
CVE-2026-76370
·
Published
2026-08-19
·
Updated
2026-08-21
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Splunk SOAR versions prior to 8.6.0
Description
An authenticated user with restricted tenant access can use the Representational State Transfer (REST) API to view the names and identifiers of tenants that are outside their assigned role scope. This occurs in deployments where multi-tenancy is enabled because the system fails to enforce role-based tenant restrictions when returning tenant information via the REST API.
Recommendations
Update to version 8.6.0 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Soar