What is CVE-2026-76366?
This vulnerability exists in Splunk SOAR versions prior to 8.6.0. An authenticated user can exploit the REST API filtering on playbook runs to recover session tokens, leading to the disclosure of all data accessible to that affected user. Immediate upgrade to the latest version is strongly recommended.
Azərbaycanca: Bu boşluq Splunk SOAR platformasının 8.6.0-dan əvvəlki versiyalarında aşkarlanıb. Təsdiqlənmiş istifadəçi REST API filtrindən istifadə edərək playbook icra qeydlərindən sessiya tokenlərini çıxara bilər ki, bu da həmin istifadəçiyə aid bütün məlumatların ələ keçirilməsinə səbəb olur. Təcili olaraq Splunk SOAR-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Splunk
FAQ2
Which versions of Splunk SOAR are affected by CVE-2026-76366?
This vulnerability exists in Splunk SOAR versions prior to 8.6.0.
How can an authenticated user exploit CVE-2026-76366?
An authenticated user can exploit the REST API filtering on playbook runs to recover session tokens.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.