Impact
The vulnerability arises because Splunk SOAR leaks session tokens in the responses of the REST API run‑playbook endpoint when filters are applied to playbook runs. An attacker who possesses a valid Splunk SOAR account can use the API to filter results and obtain session tokens that grant access to all data available to that user. This flaw results in a classic information‑disclosure weakness (CWE-200) and undermines the confidentiality of the entire dataset accessible to the compromised account.
Affected Systems
Splunk SOAR deployments with versions older than 8.6.0 are vulnerable. The affected product is Splunk SOAR from vendor Splunk. Any release below 8.6.0 exposes the session tokens via the REST API filtering feature.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity mainly due to the authentication requirement. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated Splunk SOAR user who can call the REST run‑playbook endpoint; with such access the attacker can retrieve session tokens, compromising all data available to that account. The attack vector is therefore limited to authorized users who have API privileges, but still poses a significant risk to confidentiality within the environment.
OpenCVE Enrichment