Back

MEDIUM

Information Disclosure through the REST API in Splunk SOAR

Published Aug 19, 2026

Description

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbook runs to recover session tokens that compromise all data available to the affected user. The information disclosure is possible because Splunk SOAR does not block REST API filters from matching values that responses otherwise hide. For more information see REST Run Playbook (https://help.splunk.com/en/splunk-soar/soar-cloud/rest-api-reference/run-playbook-endpoints/rest-run-playbook) in the Splunk documentation.

Affected products

Remediation

Vendor solution

Upgrade Splunk SOAR to 8.6.0 or higher.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner cisco
Published Aug 19, 2026
Updated Aug 20, 2026
Reserved Aug 19, 2026
CISA Vulnrichment
Updated Aug 20, 2026
NVD
Status Analyzed
Modified Aug 21, 2026
Red Hat
Severity n/a
Public date n/a