Impact
A path‑traversal flaw exists in Automation Broker log uploads in Splunk SOAR versions prior to 8.6.0. An actor with the OnPrem Broker role can submit a crafted filename, causing the broker to write a log file in a directory outside the intended log location. If successful, the attacker can create or overwrite arbitrary files on the system, potentially enabling persistence or tampering. The weakness directly corresponds to improper file path handling (CWE‑22).
Affected Systems
Splunk SOAR installations earlier than version 8.6.0 that allow an OnPrem Broker role to submit automation broker logs.
Risk and Exploitability
The CVSS score is 2.7, classifying the issue as low severity. No EPSS score is currently available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to possess the OnPrem Broker role, which is typically granted to trusted users or scripts. Because the privilege is not universal, the threat surface is limited to environments where the role is over‑privileged or misconfigured. Nonetheless, an attacker with this role could write arbitrary files and potentially compromise the system.
OpenCVE Enrichment