Description
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A user with a role that allows action execution can reveal a sensitive RSA SecurID token serial number by running the enable or revoke token actions in the RSA SecurID Authentication Manager app for Splunk SOAR. The token_serial parameter is not marked as a password and is displayed in cleartext in the user interface, enabling unintended disclosure of sensitive token data. External parties cannot obtain the serial simply by observing the UI; the disclosure requires legitimate action‑run privileges, so the vulnerability is limited to authenticated users with action permissions.

Affected Systems

The affected product is the RSA SecurID Authentication Manager app for Splunk SOAR from Splunk. Versions below 1.0.5 of the app are vulnerable. The fix requires Splunk SOAR 8.6.0 or higher to run the fixed app version.

Risk and Exploitability

The CVSS score is 4.3, indicating moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Attackers need access to an account that can run actions, which is a valid but restricted attack vector. Once the proper action is triggered, the token serial is exposed in cleartext, potentially allowing further compromise of RSA SecurID authentication if the token serial is used elsewhere. Due to the required privileges, the risk is confined to organizations with internal users who can trigger these actions.

Generated by OpenCVE AI on August 20, 2026 at 10:38 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the RSA SecurID Authentication Manager app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the RSA SecurID Authentication Manager app for Splunk SOAR to at least version 1.0.5, ensuring your Splunk SOAR instance is 8.6.0 or newer as required for the fix.
  • If a patch cannot be applied immediately, disable or remove the RSA SecurID Authentication Manager app for Splunk SOAR so that token actions are no longer available.
  • Review any other action parameters that handle sensitive data to confirm they are marked as password or masked; adjust the configuration or code accordingly to prevent similar disclosures.

Generated by OpenCVE AI on August 20, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk rsa Securid Authentication Manager App For Splunk Soar
Vendors & Products Splunk
Splunk rsa Securid Authentication Manager App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Rsa Securid Authentication Manager App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:31.069Z

Reserved: 2026-08-19T12:02:03.630Z

Link: CVE-2026-76383

cve-icon Vulnrichment

Updated: 2026-08-20T16:21:13.761Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:24.467

Modified: 2026-08-20T17:19:47.773

Link: CVE-2026-76383

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information