CVE-2026-76359: Path Traversal through Universal Forwarder Installer Archive Extraction in Splunk SOAR
In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer's archive extraction to write files outside the intended installation directory. The vulnerability is possible because the Universal Forwarder credentials-package extraction workflow does not verify that each archive member remains within the intended destination before extraction. For more information see Manage roles and permissions in Splunk SOAR (On-premises) (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/manage-your-splunk-soar-on-premises-users-and-accounts/manage-roles-and-permissions-in-splunk-soar-on-premises) and Configure forwarders to send SOAR data to your Splunk deployment (https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.5.0/configure-administration-settings-in-splunk-soar-on-premises/configure-forwarders-to-send-soar-data-to-your-splunk-deployment) in the Splunk documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk SOAR (on-premises)to a version that resolves this vulnerability.Fixed in 8.6.0
Event History
Frequently Asked Questions
Who can exploit this issue?
Exploitation requires a user with the Administrator role in Splunk SOAR. The affected workflow is the Universal Forwarder credentials-package extraction process.
What access and conditions are required?
An attacker needs network access and Administrator privileges, but no user interaction is required. They must be able to supply an archive whose member paths traverse outside the intended extraction directory.
Which deployments are affected?
Splunk SOAR versions below 8.6.0 are affected. The issue applies when using the Universal Forwarder installer’s credentials-package extraction workflow.
What is the impact of successful exploitation?
A malicious archive can cause files to be written outside the intended installation directory. The reported impact includes integrity and availability effects, while confidentiality impact is not indicated.