Executive brief
Splunk SOAR is a security orchestration platform used to automate incident response and security operations. A privileged user with app-install permissions could exploit a path traversal vulnerability during app installation to write files outside the intended directory, potentially leading to system compromise or unauthorized code execution.
Technical details
This is a path traversal vulnerability (CWE-22) in the app installation archive extraction routine within Splunk SOAR. The vulnerable component fails to validate that extracted file paths remain within the intended temporary directory, allowing an attacker with app-install privileges to write files to arbitrary locations on the system. The attack requires network access and valid app-install privileges. Successful exploitation can result in arbitrary file writes, potentially enabling code execution or system integrity compromise. The vulnerability is fixed in Splunk SOAR 8.6.0 and later.
Affected products
- Splunk SOAR below 8.6.0
Timeline
- 2026-08-19: disclosed