Impact
An unauthenticated attacker who can intercept or tamper with traffic between a Splunk SOAR instance and its configured CyberArk REST server can read or alter the credential data exchanged by the credential manager. The root cause is that the CyberArk REST client does not verify server certificates by default, allowing the attacker to capture or modify sensitive authentication material. This vulnerability enables an attacker to obtain, modify, or delete credential information that Splunk SOAR uses to authenticate with other systems, resulting in possible credential theft or service disruption.
Affected Systems
Splunk SOAR software versions earlier than 8.6.0 are affected. The vulnerability applies to any configuration that uses a CyberArk REST credential manager with the default (certificate verification disabled) setting.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity. No EPSS score is available, and the flaw is not listed in the CISA KEV catalog, suggesting it may currently have low exploitation prevalence but a still significant risk if an attacker gains network visibility. The attack requires interception of the network path between Splunk SOAR and the CyberArk server, which is realistic for attackers who can compromise network devices or use a man‑in‑the‑middle position. The CNA solution recommends upgrading to version 8.6.0 or later to enforce certificate validation, thereby mitigating the risk.
OpenCVE Enrichment