Description
In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role for the request and does not restrict the user-supplied file path to the intended temporary directory. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) and Splunk SOAR (On-premises) security information (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/introduction-to-splunk-soar-on-premises/splunk-soar-on-premises-security-information) in the Splunk documentation.
Published: 2026-08-19
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Splunk SOAR releases below 8.6.0 an authenticated user that has no role assigned can send a specially crafted file path in a REST API request; because the API does not enforce role checks and does not constrain the supplied path to the intended temporary directory, the attacker can perform a path traversal leading to arbitrary code execution on the host running SOAR. This flaw was identified as a path traversal weakness (CWE-22).

Affected Systems

The vulnerability affects all installations of Splunk SOAR running versions earlier than 8.6.0, including the 8.5.x series and older releases. No specific patch versions are listed beyond the upgrade to 8.6.0 or later.

Risk and Exploitability

The CVSS base score of 7.6 indicates a high severity that threatens confidentiality, integrity, and availability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog at this time. Exploitation requires authenticated access but does not require a role, so any user account lacking assigned roles can be abused. The attack vector is the REST API, with path traversal to arbitrary filesystem locations within the SOAR environment.

Generated by OpenCVE AI on August 20, 2026 at 10:10 UTC.

Remediation

Vendor Solution

Upgrade Splunk SOAR to 8.6.0 or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk SOAR to version 8.6.0 or newer to eliminate the flaw.
  • Review and assign appropriate roles to all authenticated users, removing accounts that have no role assigned to prevent abuse of the REST API.
  • Configure and enforce role‑based access controls on REST API endpoints as documented by Splunk to restrict file path handling to authorized users.

Generated by OpenCVE AI on August 20, 2026 at 10:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk soar
CPEs cpe:2.3:a:splunk:soar:*:*:*:*:on-premises:*:*:*
Vendors & Products Splunk soar

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Vendors & Products Splunk
Splunk splunk

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. The vulnerability is possible because the REST API does not require an assigned role for the request and does not restrict the user-supplied file path to the intended temporary directory. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) and Splunk SOAR (On-premises) security information (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/introduction-to-splunk-soar-on-premises/splunk-soar-on-premises-security-information) in the Splunk documentation.
Title Remote Code Execution (RCE) through Path Traversal in the REST API in Splunk SOAR
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:34.967Z

Reserved: 2026-08-19T12:02:03.628Z

Link: CVE-2026-76357

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:20.873

Modified: 2026-08-21T14:44:06.153

Link: CVE-2026-76357

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:52Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')