Back

MEDIUM

Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR

Published Aug 19, 2026

Description

In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended installation directory. The vulnerability is possible because the Universal Forwarder credentials-package extraction workflow does not verify that each archive member remains within the intended destination before extraction. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) and Configure forwarders to send SOAR data to your Splunk deployment (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/configure-administration-settings-in-splunk-soar-on-premises/configure-forwarders-to-send-soar-data-to-your-splunk-deployment) in the Splunk documentation.

Affected products

Remediation

Vendor solution

Upgrade Splunk SOAR to 8.6.0 or higher.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner cisco
Published Aug 19, 2026
Updated Aug 20, 2026
Reserved Aug 19, 2026

CISA Vulnrichment

Updated Aug 20, 2026

NVD

Status Analyzed
Modified Aug 21, 2026

Red Hat

No data

ENISA EUVD

Assigner cisco
Published Aug 19, 2026
Updated Aug 20, 2026

GitHub

No data