Description
In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In versions of the Azure AD Graph app for Splunk SOAR prior to 2.5.3 the reset password action displays the generated temporary password unmasked in the user interface. A user who has a role that permits running actions can trigger this reset and directly see a clear‑text password, exposing sensitive credentials to anyone who can view the action output. The disclosure is limited to passwords generated by the application but can compromise account security.

Affected Systems

Splunk’s Azure AD Graph app for Splunk SOAR, versions earlier than 2.5.3, on any deployment running Splunk SOAR. The fix is available only in app versions that require Splunk SOAR 8.6.0 or newer.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.3, indicating moderate risk. EPSS information is not available, so the likelihood of automated exploitation is unknown, but the attack requires a legitimate user with action‑execution privileges, meaning it is an internal risk. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread exploitation yet. Attackers must possess role permissions to run actions; no external attacker can trigger the disclosure merely by sending a request.

Generated by OpenCVE AI on August 20, 2026 at 10:40 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the Azure AD Graph app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the Azure AD Graph app for Splunk SOAR to the fixed version, which requires Splunk SOAR 8.6.0 or higher
  • If an immediate upgrade is not feasible, disable or remove the Azure AD Graph app for Splunk SOAR to prevent any reset password actions from running
  • Constrain action‑execution roles to only trusted users and audit reset password activity to detect unauthorized use

Generated by OpenCVE AI on August 20, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk azure Ad Graph App For Splunk Soar
Vendors & Products Splunk
Splunk azure Ad Graph App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in Azure AD Graph app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Azure Ad Graph App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:32.007Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76377

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:23.697

Modified: 2026-08-20T17:19:47.093

Link: CVE-2026-76377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information