Impact
The vulnerability allows an unauthenticated attacker to spoof the client‑supplied source IP header in a request to the Automation Broker notification endpoint and cause arbitrary code execution on the Splunk SOAR host. Because the broker trusts this header as proof of local origin, the attacker can run code with the host’s privileges, exposing sensitive data, corrupting system integrity, and potentially disrupting service availability.
Affected Systems
Splunk SOAR versions prior to 8.6.0 are affected. The flaw resides in the Automation Broker component that processes notification requests.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV. The most probable attack vector is an external or remote attacker submitting a crafted request to the exposed endpoint, exploiting the lack of authentication and the trust placed in the source IP header.
OpenCVE Enrichment