Junglewise Threat Intelligence

CVE-2026-76359: Splunk SOAR path traversal in Universal Forwarder installer

CVE-2026-76359 · Severity: medium · CVSS 6.5 · Published 2026-08-19

Technologies: Splunk SOAR. Vendors: Splunk.

Executive brief

Splunk SOAR is a security orchestration and automation platform used to manage security workflows and incident response. A flaw in the Universal Forwarder installer allows an administrator to write arbitrary files outside the intended installation directory, potentially enabling unauthorized code execution or system compromise on the SOAR platform.

Technical details

This is a path traversal vulnerability (CWE-22) in the Universal Forwarder credentials-package extraction workflow within Splunk SOAR versions below 8.6.0. The vulnerability exists because the archive extraction routine does not validate that extracted file paths remain within the intended destination directory before extraction. An authenticated user with the Administrator role can exploit this by crafting a malicious archive with path traversal sequences (e.g., "../") to write files to arbitrary locations on the system. No user interaction is required beyond the attacker having Administrator privileges. The fix is available in Splunk SOAR 8.6.0 and later.

Affected products

  • Splunk SOAR below 8.6.0

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Splunk SOAR 8.6.0

References

Related threats