Executive brief
Splunk SOAR is a security orchestration and automation platform used to manage security workflows and incident response. A flaw in the Universal Forwarder installer allows an administrator to write arbitrary files outside the intended installation directory, potentially enabling unauthorized code execution or system compromise on the SOAR platform.
Technical details
This is a path traversal vulnerability (CWE-22) in the Universal Forwarder credentials-package extraction workflow within Splunk SOAR versions below 8.6.0. The vulnerability exists because the archive extraction routine does not validate that extracted file paths remain within the intended destination directory before extraction. An authenticated user with the Administrator role can exploit this by crafting a malicious archive with path traversal sequences (e.g., "../") to write files to arbitrary locations on the system. No user interaction is required beyond the attacker having Administrator privileges. The fix is available in Splunk SOAR 8.6.0 and later.
Affected products
- Splunk SOAR below 8.6.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Splunk SOAR 8.6.0