What is CVE-2026-76360?
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could access administrative system telemetry via the /rest/health endpoint due to a missing authorization check. Upgrading to version 8.6.0 or later is recommended to mitigate the issue.
Azərbaycanca: Splunk SOAR-da autentifikasiya olunmuş, lakin heç bir rol təyin edilməmiş istifadəçi /rest/health endpoint-i vasitəsilə inzibati səviyyəli sistem telemetriya məlumatlarını əldə edə bilər. Bu boşluq 8.6.0-dan aşağı versiyalara təsir edir və çatışmayan avtorizasiya yoxlamasından qaynaqlanır; Splunk SOAR-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Splunk
FAQ2
Does exploiting CVE-2026-76360 require the attacker to be authenticated on the system?
Yes, to exploit this vulnerability, the user must be authenticated in Splunk SOAR, but having no role assigned is sufficient.
Which versions of Splunk SOAR are affected by CVE-2026-76360?
This vulnerability affects Splunk SOAR versions below 8.6.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.