Impact
In versions of Splunk SOAR before 8.6.0, the REST API allows a user with the Automation Engineer role to construct and execute arbitrary SQL statements that are injected directly into the database layer. The vulnerable endpoints incorporate user‑supplied input into queries without proper sanitization, enabling the attacker to create, read, update or delete any data stored in the Splunk SOAR database. This flaw is a classic instance of SQL injection (CWE-943).
Affected Systems
The affected product is Splunk SOAR for all instances where the software version is lower than 8.6.0. The issue affects only users who possess the Automation Engineer role – a privileged role that provides extensive scripting and automation capabilities within the SOAR platform.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. While the EPSS score is not available, the flaw enables full read/write/erase access to the database, which could result in data loss, corruption or disclosure. The attack vector is likely through network‑connected REST API calls; an attacker must authenticate with an Automation Engineer account to exploit the flaw. Given the scope of potential damage to all database contents, the risk remains significant even though exploitation requires a privileged user account.
OpenCVE Enrichment