Description
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In earlier releases of the AD LDAP app for Splunk SOAR, the connector writes its entire process environment to a persistent debug log when an action is invoked. A user with any role that permits action execution can trigger this behavior, thereby exposing sensitive credentials and configuration data in plaintext log files. The weakness is identified as CWE‑532, illustrating improper exposure of system information. The consequence is a confidentiality breach that can lead to credential compromise for downstream services connected through the LDAP connector.

Affected Systems

The vulnerability affects Splunk SOAR installations that include the AD LDAP app with a version earlier than 2.3.8. The remediation requires the fixed connector to be deployed on Splunk SOAR 8.6.0 or later; therefore any SOAR instance using an older core version is implicitly impacted if the app is present. Users should verify whether their environment hosts the legacy app and has a sufficient SOAR core to support the update.

Risk and Exploitability

The CVSS score of 5 points classifies this flaw as medium severity. EPSS information is not available, so the likelihood of exploitation cannot be precisely quantified. The vulnerability is not listed in KEV, indicating no publicly reported exploitation yet. The attack vector is internal: an authenticated user possessing action‑execution rights can trigger the environment dump. This requirement limits the exposure to trusted roles, but the impact of credential exposure remains significant.

Generated by OpenCVE AI on August 20, 2026 at 10:41 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the AD LDAP app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the AD LDAP connector to the latest fixed version 2.3.8 or newer, ensuring the Splunk SOAR instance is at least 8.6.0 before applying the update.
  • If upgrading the SOAR core or the connector is not currently feasible, disable or remove the AD LDAP app to stop all actions that would write the environment data.
  • After disabling, monitor system logs for any future creation of debug files that might still contain sensitive information and verify that no environment variables are exposed elsewhere.

Generated by OpenCVE AI on August 20, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk ad Ldap App For Splunk Soar
Vendors & Products Splunk
Splunk ad Ldap App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAR
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}


Subscriptions

Splunk Ad Ldap App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:32.310Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76375

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:23.450

Modified: 2026-08-20T17:19:46.863

Link: CVE-2026-76375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-532

    Insertion of Sensitive Information into Log File