Description
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read sensitive attributes from arbitrary directory objects, and redirect account modification actions to unintended objects. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AD LDAP app for Splunk SOAR is vulnerable to a filter injection attack that allows a user with action execution permissions to inject crafted input into AD queries. Exploitation can result in enumeration of accounts, groups, and organizational units, reading sensitive attributes from arbitrary directory objects, and redirecting modification actions to unintended targets. This is a CWE‑90 vulnerability that undermines confidentiality and integrity of the directory.

Affected Systems

The vulnerability affects Splunk’s AD LDAP app for Splunk SOAR versions earlier than 2.3.8. Affected installations run on Splunk SOAR 8.6.0 or higher, since the fixed app version requires that base platform. Any deployment of the app under version 2.3.8 or lower should be considered at risk.

Risk and Exploitability

The CVSS base score is 5.4, indicating a moderate severity. EPSS is not reported and the vulnerability is not in the KEV catalog. Attackers need a role that permits running actions and network access to the Splunk SOAR management interface. The injection vector likely occurs through the action parameter interface that accepts user input for AD queries.

Generated by OpenCVE AI on August 20, 2026 at 10:43 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the AD LDAP app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the AD LDAP app to version 2.3.8 or later, ensuring Splunk SOAR 8.6.0+ is installed.
  • Disable or uninstall the AD LDAP app if an upgrade cannot be performed immediately.
  • Restrict user roles so that only trusted accounts have permission to run actions, and review all action‑execution privileges.

Generated by OpenCVE AI on August 20, 2026 at 10:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk ad Ldap App For Splunk Soar
Vendors & Products Splunk
Splunk ad Ldap App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read sensitive attributes from arbitrary directory objects, and redirect account modification actions to unintended objects. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR
Weaknesses CWE-90
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Splunk Ad Ldap App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:32.626Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76373

cve-icon Vulnrichment

Updated: 2026-08-20T16:22:07.282Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:23.187

Modified: 2026-08-20T17:19:46.637

Link: CVE-2026-76373

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-90

    Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection')