Executive brief
Splunk SOAR is a security orchestration platform used to automate incident response workflows. An unauthenticated attacker with network access between SOAR and its configured CyberArk credential vault could intercept and modify all credentials and sensitive data exchanged between them, because the CyberArk REST client does not verify server certificates by default. This could lead to credential theft, unauthorized access to protected systems, and compromise of the entire credential management infrastructure.
Technical details
This vulnerability is an improper certificate validation flaw (CWE-295) in Splunk SOAR's CyberArk Vault Privileged Access Manager (PAM) REST client integration. The CyberArk REST client does not verify server certificates by default, making it vulnerable to man-in-the-middle (MITM) attacks. An unauthenticated attacker with network-path interception capability between Splunk SOAR and the configured CyberArk REST server can observe, intercept, and modify all credential data exchanged through that credential manager. The attack requires the attacker to be on the network path between SOAR and the CyberArk server. Splunk released a fix in version 8.6.0; affected versions are below 8.6.0. Additional remediation steps beyond upgrading are required.
Affected products
- Splunk SOAR below 8.6.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fix released in Splunk SOAR 8.6.0