PT-2026-78797 · Splunk · Splunk Soar

CVE-2026-76370

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Splunk SOAR versions prior to 8.6.0
Description An authenticated user with restricted tenant access can use the Representational State Transfer (REST) API to view the names and identifiers of tenants that are outside their assigned role scope. This occurs in deployments where multi-tenancy is enabled because the system fails to enforce role-based tenant restrictions when returning tenant information via the REST API.
Recommendations Update to version 8.6.0 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76370

Affected Products

Splunk Soar