Impact
The vulnerability permits a user with app-install privileges to supply a malicious archive during app installation. The extraction routine fails to validate that each file’s path remains inside the designated temporary directory, enabling the attacker to write arbitrary files beyond that location. This flaw could allow the attacker to overwrite or create system files, inject code, or otherwise tamper with the environment, potentially escalating privileges or compromising system integrity. The weakness corresponds to a classic path traversal flaw.
Affected Systems
All Splunk SOAR installations running a version older than 8.6.0 are affected. The vulnerability applies to any instance where users possess app-install roles.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. No EPSS score is available, so the current exploit probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The exploitable condition requires an authenticated attacker with app-install permissions, which is a non-trivial prerequisite but common in environments where such roles are granted. If the attacker can supply a crafted archive, they can write files outside the temporary directory, potentially leading to unauthorized persistence or code execution depending on the overwritten system components.
OpenCVE Enrichment