Junglewise Threat Intelligence

CVE-2026-76357: Splunk SOAR path traversal remote code execution in REST API

CVE-2026-76357 · Severity: high · CVSS 7.6 · Published 2026-08-19

Technologies: Splunk SOAR. Vendors: Splunk.

Executive brief

Splunk SOAR is an orchestration platform for security operations and incident response. An authenticated user without an assigned role can exploit a path traversal flaw in the REST API to execute arbitrary code on the SOAR server. This allows attackers with even basic authentication to gain full control of the security operations platform and the sensitive data it handles.

Technical details

This vulnerability is a path traversal (CWE-22) in Splunk SOAR's REST API that allows authenticated users with no role assigned to bypass file path restrictions and achieve remote code execution. The REST API fails to validate that user-supplied file paths remain within the intended temporary directory, and does not enforce role-based access control for the vulnerable endpoint. Attack requires valid authentication credentials but no specific role assignment. Successful exploitation grants arbitrary code execution with SOAR service privileges, compromising confidentiality, integrity, and availability. The fix is available in version 8.6.0 and later.

Affected products

  • Splunk SOAR below 8.6.0

Timeline

  • 2026-08-19: disclosed

References

Related threats