Description
In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking the deflate item action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an information disclosure flaw in the Phantom app for Splunk SOAR, where a user with permission to run actions can view a sensitive archive password in cleartext. The flaw occurs because the app fails to mask the password field in the deflate item action, exposing it in the UI. This leads to unauthorized exposure of credential material, compromising confidentiality for anyone with access to the interface.

Affected Systems

The affected product is the Phantom app for Splunk SOAR from Splunk, versions below 3.8.5. The fix requires Splunk SOAR 8.6.0 or higher; therefore, systems running older versions of both the app and the platform are vulnerable. The vulnerability impacts any role that can execute actions, including users with elevated permissions such as administrators or managers.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity, and the EPSS score is not available, so the current exploit probability is unclear. The vulnerability is not listed in the CISA KEV catalog, which suggests no known widespread exploitation. Attackers would need to be authenticated and have action‑execution rights, meaning only privileged account holders can exploit the weakness. Consequently, the risk is confined to users who can run actions rather than arbitrary external attackers.

Generated by OpenCVE AI on August 20, 2026 at 10:38 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the Phantom app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the Phantom app for Splunk SOAR to a version with the fix, ensuring the application runs on Splunk SOAR 8.6.0 or newer.
  • If an upgrade is not immediately possible, disable or remove the Phantom app to prevent actions from running.
  • Restrict users to roles that do not have permissions to execute actions that contain sensitive parameters until the app is patched or removed.

Generated by OpenCVE AI on August 20, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk phantom App For Splunk Soar
Vendors & Products Splunk
Splunk phantom App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking the deflate item action, because the action's password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in Phantom app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Phantom App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:31.224Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76382

cve-icon Vulnrichment

Updated: 2026-08-20T16:21:19.322Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:24.340

Modified: 2026-08-20T17:19:47.657

Link: CVE-2026-76382

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information