Executive brief
Splunk SOAR is a platform used by security teams to automate responses to cyber threats. A vulnerability in how the system records web requests allows an attacker to insert hidden formatting codes into the system's log files. If an administrator views these logs using certain command-line tools, the codes could be used to hide malicious activity or mislead the administrator by altering how the log data appears on their screen.
Technical details
A log injection vulnerability (CWE-117) exists in Splunk SOAR due to improper neutralization of control characters in HTTP request paths. An unauthenticated remote attacker can send specially crafted HTTP requests containing ANSI escape codes, which the application then writes directly to its log files. If a system administrator views these logs using a terminal emulator that interprets ANSI codes, the attacker can manipulate the terminal output to hide log entries, spoof log data, or potentially execute terminal-specific commands depending on the emulator's capabilities. This issue is resolved in Splunk SOAR version 8.5.0.
Affected products
- Splunk SOAR < 8.5.0
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory
- 2026-06-10: patched: Fixed in version 8.5.0