Description
In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive AWS credentials by invoking an action that accepts the credentials parameter, because the parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AWS IAM app for Splunk SOAR contains an unmasked credentials parameter in actions that are run by users with permission to execute them. In versions older than 2.1.9, the app does not mark this parameter as a password and displays it in cleartext in the user interface. An attacker who can trigger such an action can read the embedded AWS credentials from the UI, potentially giving them unauthorized access to AWS resources. The vulnerability results in sensitive data exposure but does not provide a pathway to arbitrary code execution or denial of service.

Affected Systems

The affected software is the Splunk AWS IAM app for Splunk SOAR. Any installation of the app with a version earlier than 2.1.9 is vulnerable. The remedy requires Splunk SOAR version 8.6.0 or later. Users of the older app versions should upgrade to the fixed release to block the disclosure.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the vulnerability is not listed in CISA's KEV catalog. The EPSS is not available, so the exact exploitation likelihood is unknown. The attack vector is limited to users who have rights to run actions; they can trigger a vulnerable action and view its output in the interface. While the exposure of credentials is serious, the requirement to log in and have action execution rights reduces the attack surface to authorized users or insiders.

Generated by OpenCVE AI on August 20, 2026 at 10:41 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the AWS IAM app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the AWS IAM app for Splunk SOAR to version 2.1.9 or later, ensuring Splunk SOAR is 8.6.0 or higher.
  • If an upgrade is not immediately possible, disable or remove the AWS IAM app for Splunk SOAR to prevent any action execution that could leak credentials.
  • Limit action‑executing permissions to only trusted users and review role assignments regularly.

Generated by OpenCVE AI on August 20, 2026 at 10:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk aws Iam App For Splunk Soar
Vendors & Products Splunk
Splunk aws Iam App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive AWS credentials by invoking an action that accepts the credentials parameter, because the parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in AWS IAM app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Aws Iam App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:32.157Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76376

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:23.577

Modified: 2026-08-20T17:19:46.983

Link: CVE-2026-76376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information