{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/soar/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.6,"id":"CVE-2026-76357"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SOAR (8.5.0)","SOAR"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","splunk"],"_cs_type":"advisory","_cs_vendors":["Splunk"],"content_html":"\u003cp\u003eSplunk SOAR versions below 8.6.0 contain a critical vulnerability identified as CVE-2026-76357, which allows authenticated users without assigned roles to achieve arbitrary code execution. The vulnerability is rooted in the REST API's failure to enforce role-based access controls for specific requests and a lack of input validation regarding file path parameters. An attacker can submit a crafted file path to the API, bypassing directory restrictions to execute arbitrary code on the underlying host. This vulnerability poses a significant risk to organizational environments relying on Splunk SOAR for security orchestration and response, as it enables unauthorized system-level operations by low-privileged authenticated accounts. Defenders should prioritize patching all Splunk SOAR instances to version 8.6.0 or higher.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to execute arbitrary code with the privileges of the Splunk SOAR service account. This could lead to full compromise of the SOAR platform, lateral movement within the network, and the potential exfiltration or manipulation of sensitive security orchestration data. Organizations using Splunk SOAR for automated incident response are at high risk if default or low-privileged accounts are compromised.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Splunk SOAR (On-premises) to version 8.6.0 or higher immediately.\u003c/li\u003e\n\u003cli\u003eReview user accounts and role assignments within the Splunk SOAR platform to ensure the principle of least privilege is applied, specifically limiting access to REST API endpoints.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the SOAR REST API to identify anomalous requests involving directory traversal patterns (e.g., ../, .., or absolute file paths) originating from unprivileged or newly created service accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-20T13:11:33Z","date_published":"2026-08-19T22:43:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-splunk-soar-rce/","summary":"Splunk SOAR versions prior to 8.6.0 are vulnerable to authenticated remote code execution due to improper path validation and insufficient role-based access control on the REST API.","title":"Arbitrary Code Execution in Splunk SOAR via Path Traversal","url":"https://feed.craftedsignal.io/briefs/2026-08-splunk-soar-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - SOAR","version":"https://jsonfeed.org/version/1.1"}