Executive brief
Splunk SOAR's Nmap Scanner connector contains a permission bypass vulnerability that allows authenticated users with playbook editing privileges to run unrestricted network scanning actions marked as read-only. An attacker could exploit this to execute arbitrary Nmap scripts that modify or compromise target systems, even in restricted Safe Mode playbooks where such actions should be prohibited.
Technical details
The vulnerability is an incorrect permission assignment (CWE-732) in the Nmap Scanner connector for Splunk SOAR versions below 3.0.15. The connector's action manifest incorrectly classifies the "scan network" action as read-only in Safe Mode playbooks, despite accepting script parameters that permit write operations and arbitrary command execution through Nmap Scripting Engine (NSE) scripts. An authenticated attacker with a role that can edit, create, or run playbooks can execute the scan network action with NSE scripts that modify target systems. The vulnerability requires valid Splunk SOAR credentials and the ability to author or execute playbooks but does not require elevated admin privileges. Splunk has released version 3.0.15 as a fix.
Affected products
- Splunk Nmap Scanner below 3.0.15
Timeline
- 2026-08-19: disclosed