Impact
The vulnerability is a Server‑Side Request Forgery that allows a user with the Administrator role to trigger outbound connections from Splunk SOAR to arbitrary destinations through the /rest/support/connectivity/.../check_connectivity endpoint. The API lacks proper validation of the target, enabling the internal network to be scanned or data retrieved from internal hosts and ports. The weakness is classified as CWE‑918, and the impact is primarily the ability to discover and potentially exploit internal resources, rather than direct code execution.
Affected Systems
Splunk SOAR (On‑premises) versions prior to 8.6.0 are affected. Any deployment of Splunk SOAR where the connectivity check API is enabled and an Administrator account exists may be vulnerable.
Risk and Exploitability
The CVSS score of 2.7 indicates limited severity. The EPSS score is not available, so the likelihood of exploitation is unknown but potentially low. The vulnerability is not listed in the CISA KEV catalog, and no publicly reported exploits exist. Nonetheless, exploitation requires Administrator credentials; once achieved, an attacker can use the SSRF to probe or interact with internal hosts, which could lead to further compromise. Reducing the number of Administrators, restricting outbound connections, and applying the vendor patch are recommended mitigations.
OpenCVE Enrichment