Impact
In Splunk SOAR releases before 8.6.0, the /rest/health API endpoint lacks an authorization check. An authenticated user who has no role assignment can call the endpoint and receive system and cluster telemetry that should only be available to administrators or support staff. The flaw can expose configuration details, version information, and cluster state, thereby compromising the confidentiality of the platform’s operational data.
Affected Systems
Affected vendors include Splunk; the product is Splunk SOAR. All versions earlier than 8.6.0 contain the vulnerability. No specific minor releases are listed, but any installation using a pre‑8.6.0 build is potentially impacted.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate severity for an unauthorized data exposure. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation. The attack vector requires authentication but does not require privileged roles; therefore, any user account that can authenticate without being assigned a role could leverage the flaw to obtain sensitive system telemetry.
OpenCVE Enrichment