Description
In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In earlier releases of the Cisco Secure Malware Analytics app for Splunk SOAR, the detonate file action exposes the sample_password parameter in cleartext. A user with permission to run actions can invoke this action and see the password displayed in the user interface, constituting a disclosure of sensitive credentials. The weakness is a failure to mask the parameter, identified as CWE-312.

Affected Systems

The flaw affects the Cisco Secure Malware Analytics app for Splunk SOAR versions earlier than 2.4.5. The mitigation requires the app to be upgraded to a fixed version, which itself requires Splunk SOAR 8.6.0 or newer.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.3, indicating a low-to-medium severity. The EPSS score is not available, so the precise likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would need a role that can run actions; the disclosure is therefore limited to internal users with sufficient privileges.

Generated by OpenCVE AI on August 20, 2026 at 10:40 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the Cisco Secure Malware Analytics app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the Cisco Secure Malware Analytics app to a version fixed for the vulnerability, ensuring the underlying Splunk SOAR platform is 8.6.0 or newer.
  • If an upgrade cannot be performed immediately, disable or remove the app from Splunk SOAR to prevent the action from running.
  • Verify that no remaining roles retain permissions to run the detonate file action until the fix is applied.

Generated by OpenCVE AI on August 20, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk cisco Secure Malware Analytics App For Splunk Soar
Vendors & Products Splunk
Splunk cisco Secure Malware Analytics App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in Cisco Secure Malware Analytics app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Cisco Secure Malware Analytics App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:31.852Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76378

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:23.823

Modified: 2026-08-20T17:19:47.210

Link: CVE-2026-76378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information