Executive brief
Splunk SOAR is a security orchestration platform used to automate incident response workflows. A user with the OnPrem Broker role can craft malicious filenames to write files outside the intended Automation Broker log directory, potentially allowing unauthorized file creation in sensitive locations on the system.
Technical details
A path traversal vulnerability exists in the Automation Broker log upload functionality in Splunk SOAR versions prior to 8.6.0. The vulnerability arises because the log upload feature accepts user-controlled filename input without proper validation or sanitization before writing files to disk. An attacker with the OnPrem Broker role can craft filenames containing path traversal sequences (e.g., "../") to write files outside the intended log directory. This requires authentication with the OnPrem Broker role and network access to the Automation Broker endpoint. The attack allows arbitrary file writes to the filesystem, potentially enabling configuration tampering or privilege escalation. The fix is available in version 8.6.0 and higher.
Affected products
- Splunk SOAR below 8.6.0
Timeline
- 2026-08-19: disclosed