Description
In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The connector failed to mask the archive_password parameter when running detonate file or detonate url actions. Users with permission to execute actions can view the clear‑text password in the UI, exposing the credential that protects the encrypted archive. This disclosure could allow an attacker to decrypt the archive or reuse the password for other systems, directly compromising data confidentiality.

Affected Systems

Splunk Attack Analyzer Connector for Splunk SOAR versions earlier than 2.2.1 on Splunk SOAR 8.6.0 or higher. The issue exists only in versions below 2.2.1; upgrading to the fixed release or removing the app mitigates the problem.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact. EPSS information is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. Exploitation requires a user with action‑execution rights, so the attack vector is internal. An attacker could read the password from the UI, then use it to decrypt or otherwise compromise the archive.

Generated by OpenCVE AI on August 20, 2026 at 10:37 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the Splunk Attack Analyzer Connector for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade Splunk Attack Analyzer Connector to version 2.2.1 or later while ensuring Splunk SOAR is 8.6.0 or higher.
  • If immediate upgrade is not possible, disable or remove the connector to stop all actions derived from it.
  • Restrict action‑run permissions to trusted roles or apply least‑privilege policies to limit exposure of sensitive parameters.

Generated by OpenCVE AI on August 20, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk Attack Analyzer Connector For Splunk Soar
Vendors & Products Splunk
Splunk splunk Attack Analyzer Connector For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in Splunk Attack Analyzer Connector for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Splunk Attack Analyzer Connector For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:30.917Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76384

cve-icon Vulnrichment

Updated: 2026-08-20T16:21:07.956Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:24.587

Modified: 2026-08-20T17:19:47.890

Link: CVE-2026-76384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information