Splunk App for SOAR Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability exists in the Splunk App for SOAR, specifically in versions 1.0.67 and earlier. The issue arises because the Splunk documentation for these versions recommended granting the 'admin_all_objects' capability to the 'splunk_app_soar' role. This could result in improper access control, allowing low-privileged users without 'admin' roles to gain elevated permissions.

Impact

Exploitation of this vulnerability allows low-privileged users with the 'splunk_app_soar' role to gain unauthorized access rights, potentially leading to elevated privileges within the Splunk environment.

Remediation

Users who have not modified the 'splunk_app_soar' role should upgrade to version 1.0.71 or higher. Those who have made changes to the role should manually delete it or remove any high-privileged capabilities before upgrading. For more details, consult the Splunk documentation on roles and capabilities.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.