Description
In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked and are shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameters as passwords. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Venafi app for Splunk SOAR released before version 2.1.4 contains an information disclosure flaw. The app’s get‑certificate action exposes keystore and private‑key passwords in cleartext because the action parameters are not masked. As a result, a user with a role that permits running actions could capture sensitive credentials directly from the Splunk SOAR user interface. The weakness corresponds to CWE‑312, representing cleartext storage of sensitive information. The impact is a confidentiality breach that could allow attackers to access secured resources or compromise further system components.

Affected Systems

The vulnerability affects the Venafi app for Splunk SOAR from Splunk. All releases prior to 2.1.4 are vulnerable. In addition, the fixed app requires Splunk SOAR 8.6.0 or higher, so any environment using an earlier SOAR version cannot immediately deploy the patched connector.

Risk and Exploitability

The CVSS score for the issue is 4.3, indicating low overall severity, and the EPSS score is not available, suggesting no publicly known exploitation activity. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires a user with credentials that grant the ability to run actions within Splunk SOAR; the attacker must access the web console and invoke the get‑certificate action. Because the exposure is triggered by a legitimate UI function, the attack vector is internal and dependent on privileged user access. While the risk is moderate due to the confidence of data leakage, stakeholders should consider the business impact if sensitive credentials are compromised.

Generated by OpenCVE AI on August 20, 2026 at 10:37 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the Venafi app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Apply the vendor‑supplied update for all Venafi connectors below 2.1.4.
  • Confirm the underlying Splunk SOAR instance meets the minimum required version of 8.6.0 before installing the updated app.
  • If an update is not immediately feasible, disable or remove the Venafi app for Splunk SOAR to eliminate the vulnerable action endpoint.

Generated by OpenCVE AI on August 20, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk venafi App For Splunk Soar
Vendors & Products Splunk
Splunk venafi App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked and are shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameters as passwords. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in Venafi app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Venafi App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T16:27:30.760Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76385

cve-icon Vulnrichment

Updated: 2026-08-20T16:21:02.407Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:24.710

Modified: 2026-08-20T17:19:47.997

Link: CVE-2026-76385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information