Executive brief
Splunk SOAR is a security orchestration and automation platform used to automate incident response workflows. In versions before 8.6.0, users with basic playbook viewing permissions could view metadata about playbook repositories they should not have access to due to insufficient permission checks in the Playbook History function. This allows unauthorized information disclosure about automation configurations.
Technical details
The vulnerability is a missing authorization check (CWE-862) in the Playbook History component of Splunk SOAR. When a user holds a role with the playbooks:view permission, the Playbook History endpoint returns revision metadata without verifying that the user has authorization to access the specific playbook repository. The vulnerability requires an authenticated user with at least the playbooks:view permission; exploitation results in unauthorized disclosure of playbook repository metadata. The fix is available in Splunk SOAR 8.6.0 and later.
Affected products
- Splunk SOAR below 8.6.0
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fix available in Splunk SOAR 8.6.0