Description
In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For more information see Manage roles and permissions in Splunk SOAR (Cloud) (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) and About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.
Published: 2026-08-19
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path‑traversal flaw exists in Automation Broker log uploads in Splunk SOAR versions prior to 8.6.0. An actor with the OnPrem Broker role can submit a crafted filename, causing the broker to write a log file in a directory outside the intended log location. If successful, the attacker can create or overwrite arbitrary files on the system, potentially enabling persistence or tampering. The weakness directly corresponds to improper file path handling (CWE‑22).

Affected Systems

Splunk SOAR installations earlier than version 8.6.0 that allow an OnPrem Broker role to submit automation broker logs.

Risk and Exploitability

The CVSS score is 2.7, classifying the issue as low severity. No EPSS score is currently available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to possess the OnPrem Broker role, which is typically granted to trusted users or scripts. Because the privilege is not universal, the threat surface is limited to environments where the role is over‑privileged or misconfigured. Nonetheless, an attacker with this role could write arbitrary files and potentially compromise the system.

Generated by OpenCVE AI on August 20, 2026 at 10:44 UTC.

Remediation

Vendor Solution

Upgrade Splunk SOAR to 8.6.0 or higher.


OpenCVE Recommended Actions

  • Upgrade Splunk SOAR to version 8.6.0 or later.
  • Revoke the OnPrem Broker role from users or processes that do not truly require it, enforcing least privilege.
  • Validate that the automation broker log directory permissions restrict write access to the intended service account and monitor for unexpected file creation.

Generated by OpenCVE AI on August 20, 2026 at 10:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Splunk soar
CPEs cpe:2.3:a:splunk:soar:*:*:*:*:cloud:*:*:*
Vendors & Products Splunk soar

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk
Vendors & Products Splunk
Splunk splunk

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For more information see Manage roles and permissions in Splunk SOAR (Cloud) (https://help.splunk.com/en/splunk-soar/soar-cloud/administer-soar-cloud/manage-your-splunk-soar-cloud-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-cloud) and About Splunk SOAR Automation Broker (https://help.splunk.com/en/splunk-soar/splunk-automation-broker/about-splunk-soar-automation-broker/about-splunk-soar-automation-broker) in the Splunk documentation.
Title Path Traversal through Automation Broker in Splunk SOAR
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:33.263Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76369

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:22.607

Modified: 2026-08-21T14:46:18.330

Link: CVE-2026-76369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:02:33Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')