Description
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AD LDAP app for Splunk SOAR contains a flaw in versions earlier than 2.3.8 where Active Directory response data is written to a persistent debug log when an action is triggered. This exposes confidential information such as usernames, group memberships, and potentially passwords if they appear in the response. Based on the description, it is inferred that a user who can read the log file could obtain these sensitive details, but the CVE does not explicitly state that passwords are exposed, so that inference must be noted as derived from the available information.

Affected Systems

Splunk’s AD LDAP app for Splunk SOAR versions below 2.3.8 are affected. The fix requires the application to be updated to a version that is compatible with Splunk SOAR 8.6.0 or newer. Administrators should verify that their Splunk SOAR instance meets the minimum base version before installing the patched app.

Risk and Exploitability

The CVSS v3.1 base score of 4.3 indicates the vulnerability's severity but the CVE data does not assign a specific risk level. The EPSS score is not available, so no assessment of exploitation probability can be made from that metric. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely exploited yet. Insufficient data is available to confirm external exposure; the likely attack vector is inferred to be an authenticated internal user with permission to run actions, which is required to trigger the logging of sensitive data.

Generated by OpenCVE AI on August 20, 2026 at 11:19 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the AD LDAP app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the AD LDAP app for Splunk SOAR to version 2.3.8 or later, ensuring it is installed on Splunk SOAR 8.6.0 or newer.
  • If the Splunk SOAR platform is older than 8.6.0, upgrade the platform first to meet the compatibility requirement before applying the updated app.
  • If an upgrade cannot be performed immediately, disable or remove the AD LDAP app to stop actions that could log sensitive Active Directory response data.

Generated by OpenCVE AI on August 20, 2026 at 11:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk ad Ldap App For Splunk Soar
Vendors & Products Splunk
Splunk ad Ldap App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Sensitive Data Logging in AD LDAP app for Splunk SOAR
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Ad Ldap App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:32.464Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76374

cve-icon Vulnrichment

Updated: 2026-08-20T16:22:01.839Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:23.323

Modified: 2026-08-20T17:19:46.750

Link: CVE-2026-76374

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:30:16Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File