← All Advisories

Splunk SOAR CyberArk REST Client Skips Server Certificate Verification by Default, Exposing Credentials to a Network-Path Attacker

Last refreshed2026-09-29

Status: UPDATED  |  Advisory ID: CVE-2026-76362

Key Details

CVECVE-2026-76362
CVSS Score / Version7.4 (High) / CVSS v3.1
Updated2026-08-21
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CVSS Proseattack vector is network; attack complexity is high; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is none.
Affected productsSplunk soar
Classified asCWE-295 (Improper Certificate Validation)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Splunksoar
SubsystemsGeneral OT
SectorsMultiple

What to Know

In Splunk SOAR versions below 8.6.0, an unauthenticated user who can observe or alter network traffic between Splunk SOAR and a configured CyberArk Representational State Transfer (REST) server could access or modify all relevant data exchanged through that credential manager. The vulnerability is possible because the CyberArk REST client does not verify server certificates by default. The attack requires the attacker to have network-path interception capability between Splunk SOAR and the configured CyberArk REST server. For more information see Manage your organization's credentials with a password vault (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/configure-administration-settings-in-splunk-soar-cloud/manage-your-organizations-credentials-with-a-password-vault) in the Splunk documentation. (NVD)

What to Do

Monitor Splunk's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-76362
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-76362
Vendor advisoryhttps://advisory.splunk.com/advisories/SVD-2026-0804