Impact
The vulnerability is an SQL injection that allows an Automation Engineer role to execute arbitrary SQL against the Splunk SOAR database through custom function results. This can lead to reading all data stored in the database and potentially altering or destroying data, thereby compromising confidentiality and integrity.
Affected Systems
Splunk SOAR versions prior to 8.6.0 are affected. The attacker must possess the Automation Engineer role to exploit the flaw.
Risk and Exploitability
The CVSS score of 6.5 classifies this as a medium‑severity vulnerability, and the EPSS score is not available, indicating no publicly reported exploitation patterns. The vulnerability is not listed in the CISA KEV catalog. Because it requires an authenticated Automation Engineer, exploitation is limited to users with that role within the organization, but an insider or compromised account could abuse it to read or modify database contents.
OpenCVE Enrichment