Description
In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are not masked and are shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameters as passwords. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Zoom app for Splunk SOAR in versions earlier than 3.2.2 leaves action parameters for passwords and personal meeting IDs in cleartext. A user with a role that allows running actions can invoke actions such as create meeting, update meeting, or update user settings and see the credentials displayed in the interface, exposing sensitive meeting and personal meeting ID passwords to the attacker. This constitutes an information‑disclosure vulnerability that compromises confidentiality of Zoom meeting data.

Affected Systems

Splunk SOAR installations that use the Zoom app for Splunk SOAR version 3.2.1 or earlier run on Splunk SOAR 8.6.0 or higher. Any user with a role that grants permission to execute these actions on those versions is affected.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity. No EPSS score is available and the issue is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation. The vulnerability can be abused by any user who has legitimate action‑execution rights; the attack vector is therefore internal, relying on authorized access rather than remote code execution. Exploitation results in the disclosure of meeting passwords, potentially enabling unauthorized participation in Zoom meetings.

Generated by OpenCVE AI on August 20, 2026 at 10:36 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk SOAR connector to the applicable fixed version listed in Product Status. The fixed app version requires Splunk SOAR 8.6.0 or higher.


Vendor Workaround

Turn off or remove the Zoom app for Splunk SOAR. For more information see [Add and configure apps and assets to provide actions in Splunk SOAR](https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/8.6.0/manage-your-splunk-soar-on-premises-apps-and-assets/add-and-configure-apps-and-assets-to-provide-actions-in-splunk-soar-on-premises) in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.


OpenCVE Recommended Actions

  • Upgrade the Zoom app for Splunk SOAR to the fixed version that requires Splunk SOAR 8.6.0 or higher
  • If upgrading is not possible, disable or remove the Zoom app for Splunk SOAR to prevent the exposed actions from running
  • Limit or revoke role permissions that allow action execution to trusted users only

Generated by OpenCVE AI on August 20, 2026 at 10:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk zoom App For Splunk Soar
Vendors & Products Splunk
Splunk zoom App For Splunk Soar

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected password and pmi_password parameters are not masked and are shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameters as passwords. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Title Information Disclosure through Action Parameters in Zoom app for Splunk SOAR
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk Zoom App For Splunk Soar
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:26:32.588Z

Reserved: 2026-08-19T12:02:03.631Z

Link: CVE-2026-76386

cve-icon Vulnrichment

Updated: 2026-08-20T15:24:42.070Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-19T22:17:24.833

Modified: 2026-08-20T16:18:12.640

Link: CVE-2026-76386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information