Executive brief
FireAMP is a connector for Splunk SOAR (a security orchestration platform) that integrates malware detection and file list management capabilities. The vulnerability allows authorized playbook users to execute the "add listitem" action in Safe Mode playbooks even though it should be restricted as read-only, potentially allowing unauthorized changes to file lists used for security enforcement.
Technical details
This is a permission assignment vulnerability (CWE-732) affecting the FireAMP connector for Splunk SOAR versions below 2.1.15. The root cause is that the action manifest for the "add listitem" action incorrectly classifies it as read-only in Safe Mode, despite the action actually modifying file lists. An attacker with a role that permits editing, creating, or running playbooks can bypass Safe Mode restrictions and execute this action to make unauthorized changes to protected file lists. The vulnerability requires existing Splunk SOAR access and a permissive role assignment; network reachability to the Splunk SOAR instance is a prerequisite. Patches are available in FireAMP version 2.1.15 and later.
Affected products
- Splunk FireAMP below 2.1.15
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in version 2.1.15