PT-2026-78784 · Splunk · Splunk Soar
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk SOAR versions prior to 8.6.0
Description
An authenticated user without an assigned role can execute arbitrary code by submitting a crafted file path to the Representational State Transfer (REST) API. This occurs because the REST API does not enforce role requirements for requests and fails to restrict user-supplied file paths to the designated temporary directory.
Recommendations
Update to version 8.6.0 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Soar