Impact
The flaw lets a user who has the playbooks:view permission see metadata for a playbook repository they are not authorized to access. The vulnerability uses an existing privilege that is supposed to be check‑limited to a repository’s own metadata, so the attacker gains only non‑confidential data but the data may reveal the presence of restricted playbooks. The weakness is an improper authorization check, identified as CWE‑862, and can leak sensitive information without allowing code execution or denial of service.
Affected Systems
The issue affects Splunk SOAR installations running any version earlier than 8.6.0. Users of those versions who have been granted the playbooks:view role are the most likely to be impacted, regardless of the deployment environment (cloud or on‑premise).
Risk and Exploitability
The CVSS score of 2.7 reflects a low severity impact. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires the target to already hold a view‑permission role, the threat vector is internal and the exploitation potential is limited to organizational insiders or compromised privileged accounts. The risk to broader external attackers is minimal, but within the organization the exposure of metadata could assist other malicious activity.
OpenCVE Enrichment