Description
In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CrowdStrike OAuth API app for Splunk SOAR, versions before 5.1.3, does not mask the document_password field in the detonate file or detonate URL actions. When an authorized user runs these actions, the password is displayed in clear text in the UI, allowing disclosure of confidential credential data. This flaw is identified as an information‑disclosure weakness (CWE‑312).

Affected Systems

Affected versions are all releases of the app before 5.1.3 that run on Splunk SOAR. The fixed app requires Splunk SOAR 8.6.0 or newer. Users with roles that can execute actions against the app, such as analysts or administrators, are potentially impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available, so the probability of threat currently is unconstrained. The vulnerability is not listed in the CISA KEV catalog. The only known attack path is an internal user with sufficient action‑execution rights. An attacker who can run the detonate actions can view the document password in the interface, leaking sensitive credential information. The flaw is mitigated by applying the fixed app version or disabling the app if upgrading is not possible.

Generated by OpenCVE AI on August 20, 2026 at 10:39 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the CrowdStrike OAuth API app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the CrowdStrike OAuth API app for Splunk SOAR to the fixed version (requires Splunk SOAR 8.6.0 or later).
  • If an upgrade is not feasible, disable or remove the CrowdStrike OAuth API app for Splunk SOAR to stop all related actions.
  • Verify that users only have the minimum permissions necessary to run actions and avoid granting global action‑execution rights.

Generated by OpenCVE AI on August 20, 2026 at 10:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk crowdstrike Oauth Api App For Splunk Soar
Vendors & Products Splunk
Splunk crowdstrike Oauth Api App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in CrowdStrike OAuth API app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Crowdstrike Oauth Api App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:31.536Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76380

cve-icon Vulnrichment

Updated: 2026-08-20T16:21:29.884Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:24.077

Modified: 2026-08-20T17:19:47.437

Link: CVE-2026-76380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information