What is CVE-2026-76368?
In Splunk SOAR versions below 8.6.0, a user with the 'playbooks:view' permission can view metadata about a playbook repository they are not authorized to access. This is due to Playbook History not checking repository permissions before returning data. Upgrading to Splunk SOAR 8.6.0 or later is recommended.
Azərbaycanca: Splunk SOAR platformasının 8.6.0-dan əvvəlki versiyalarında, 'playbooks:view' icazəsi olan istifadəçi icazəsi olmayan playbook repository haqqında metadata görə bilər. Bu boşluq Playbook History funksiyasının repository icazələrini yoxlamamasından qaynaqlanır. Splunk SOAR-ı 8.6.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Splunk
FAQ2
What information can a user with the 'playbooks:view' permission access in Splunk SOAR?
The user can view metadata about a playbook repository they are not authorized to access.
What is the root cause of this vulnerability?
Playbook History does not check repository permissions before returning data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.