Product
Splunk SOAR versions prior to 8.6.0 are vulnerable to authenticated remote code execution due to improper path validation and insufficient role-based access control on the REST API.