Impact
In Splunk SOAR releases below 8.6.0 an authenticated user that has no role assigned can send a specially crafted file path in a REST API request; because the API does not enforce role checks and does not constrain the supplied path to the intended temporary directory, the attacker can perform a path traversal leading to arbitrary code execution on the host running SOAR. This flaw was identified as a path traversal weakness (CWE-22).
Affected Systems
The vulnerability affects all installations of Splunk SOAR running versions earlier than 8.6.0, including the 8.5.x series and older releases. No specific patch versions are listed beyond the upgrade to 8.6.0 or later.
Risk and Exploitability
The CVSS base score of 7.6 indicates a high severity that threatens confidentiality, integrity, and availability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog at this time. Exploitation requires authenticated access but does not require a role, so any user account lacking assigned roles can be abused. The attack vector is the REST API, with path traversal to arbitrary filesystem locations within the SOAR environment.
OpenCVE Enrichment