Impact
The vulnerability enables an Incident Commander in Splunk SOAR to embed JavaScript into a note that will be rendered as HTML when another user opens the note. The script runs in the victim’s browser with the victim’s privileges, potentially allowing session hijacking, data theft, or other malicious actions. This is a stored cross‑site scripting flaw, identified as CWE‑79.
Affected Systems
Splunk SOAR versions earlier than 8.6.0 are affected. The flaw exploits the Incident Commander role, which allows a user to create notes that are treated as HTML. Users with this role in affected versions can store and then trigger malicious content through notes. Versions 8.6.0 and later are not affected.
Risk and Exploitability
The CVSS score is 4, indicating moderate risk. EPSS data is unavailable and the vulnerability does not appear in the CISA KEV catalog. Exploitation requires the attacker to convince a target user to open a maliciously crafted note, making it a phishing‑dependent attack. Because the Incident Commander role is not intended for arbitrary code injection, the attack surface is limited to users with that role, reducing overall threat exposure.
OpenCVE Enrichment