Executive brief
Splunk SOAR is a security orchestration platform used to automate incident response workflows. A user with the "Incident Commander" role can inject malicious JavaScript into note fields that executes in other users' browsers when they view the note, potentially allowing account takeover or unauthorized actions. The attack requires social engineering to trick a victim into opening a specially crafted note.
Technical details
This is a stored cross-site scripting (XSS) vulnerability (CWE-79) in Splunk SOAR's note handling functionality. The vulnerability occurs when the format of a note is changed; SOAR treats existing note content as HTML without sanitizing it, allowing an attacker with the "Incident Commander" role to store malicious JavaScript that executes in a victim's browser. The attack vector is network-based and requires the attacker to trick a user into opening the malicious note (phishing). An attacker can achieve session hijacking, credential theft, or unauthorized actions within the victim's session. The vulnerability affects versions below 8.6.0 and is resolved by upgrading to version 8.6.0 or later.
Affected products
- Splunk SOAR Below 8.6.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fix available in version 8.6.0