SVD-2026-0804: Security Hardening Release for Splunk SOAR - August 2026 Splunk Security Announcements / 19h In Splunk SOAR versions below 8.6.0, an authenticated user with no role assigned could submit a crafted file path to the Representational State Transfer (REST) API and execute arbitrary code. In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal Forwarder installer’s archive extraction to write files outside the intended inst