What is CVE-2026-76370?
In Splunk SOAR versions below 8.6.0, an authenticated user with restricted tenant access can use the REST API to view names and identifiers of tenants outside their role scope. This vulnerability arises from improper enforcement of tenant access controls, potentially exposing sensitive tenant information. Upgrading to Splunk SOAR version 8.6.0 or later is recommended.
Azərbaycanca: Splunk SOAR-ın 8.6.0-dan əvvəlki versiyalarında, məhdud icarəçi girişinə malik autentifikasiya olunmuş istifadəçi REST API vasitəsilə öz rol dairəsindən kənarda qalan icarəçilərin adlarını və identifikatorlarını görə bilir. Bu zəiflik məxfi icarəçi məlumatlarının ifşasına səbəb ola bilər. Splunk SOAR-ı ən azı 8.6.0 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of Splunk SOAR are affected by CVE-2026-76370?
This vulnerability affects Splunk SOAR versions below 8.6.0.
What sensitive information could be exposed if CVE-2026-76370 is exploited?
Confidential tenant information such as names and identifiers of tenants outside the user's role scope could be exposed.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.