Description
In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerable version of the Cisco Webex app for Splunk SOAR discloses sensitive meeting passwords through the schedule meeting action. The action parameter that holds the password is not marked as a password, so it is rendered in cleartext in the Splunk SOAR user interface for any user who has permission to run actions. This satisfies CWE‑312, Sensitive Data Exposure, and could reveal credentials used for Webex meetings to the viewing user.

Affected Systems

The issue affects the Cisco Webex app for Splunk SOAR in all releases prior to 2.2.1. The fixed app requires Splunk SOAR version 8.6.0 or higher. The product is published by Splunk under the name Cisco Webex app for Splunk SOAR.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate impact. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting the exploitation probability is not well documented. Exploitation requires a user with the ability to execute actions within Splunk SOAR, which is typically an internal role, so the attack vector is likely limited to authenticated internal users.

Generated by OpenCVE AI on August 20, 2026 at 10:39 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the Cisco Webex app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the Cisco Webex app for Splunk SOAR to a version that requires Splunk SOAR 8.6.0 or higher and includes the fixed release.
  • Ensure that the Splunk SOAR platform itself is at least version 8.6.0 to support the updated app, upgrading if necessary.
  • As a stop‑gap, disable or remove the Cisco Webex app for Splunk SOAR, which prevents all actions that use the app from running.

Generated by OpenCVE AI on August 20, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk cisco Webex App For Splunk Soar
Vendors & Products Splunk
Splunk cisco Webex App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in Cisco Webex app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Cisco Webex App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:31.698Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76379

cve-icon Vulnrichment

Updated: 2026-08-20T16:21:35.269Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:23.950

Modified: 2026-08-20T17:19:47.320

Link: CVE-2026-76379

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information