VYPR
Medium severity4.3NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026

CVE-2026-20260

CVE-2026-20260

Description

Splunk SOAR versions below 8.5.0 are vulnerable to log injection via crafted HTTP request paths, potentially leading to terminal interpretation of ANSI escape codes.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Splunk SOAR versions below 8.5.0 are vulnerable to log injection via crafted HTTP request paths, potentially leading to terminal interpretation of ANSI escape codes.

Vulnerability

In Splunk SOAR (Security Orchestration, Automation, and Response) versions prior to 8.5.0, an unauthenticated attacker can inject ANSI escape codes into application log files. This occurs because the application does not remove control characters from HTTP request paths before logging them, allowing specially crafted paths to be written to the logs [1].

Exploitation

An unauthenticated attacker can exploit this vulnerability by sending specially crafted HTTP requests with paths containing ANSI escape codes. When an administrator views these logs using a terminal emulator, the escape codes may be interpreted, leading to the intended malicious effect [1].

Impact

Successful exploitation allows an attacker to inject arbitrary ANSI escape codes into Splunk SOAR application logs. When these logs are viewed in a terminal, these codes can be interpreted, potentially leading to visual manipulation or other unintended behaviors within the terminal session of the administrator viewing the logs. The exact impact depends on the terminal emulator's interpretation of the injected codes [1].

Mitigation

Upgrade Splunk SOAR to version 8.5.0 or later to address this vulnerability. Splunk is actively monitoring and patching Splunk SOAR on Splunk Cloud Platform instances. No specific workarounds are listed in the available references [1].

AI Insight generated on Jun 10, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1