Description
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/administer-the-app-key-value-store/about-the-app-key-value-store) in the Splunk documentation.
Published: 2026-08-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In versions prior to 1.0.43, the Splunk On-Call (VictorOps) app stores an API key in a KV Store without fully masking it, allowing users without admin or power privileges to read a partially masked key. This leads to unauthorized disclosure of sensitive credentials used by the application, exposing potential service access. The weakness is a CWE‑312 type information‑leak flaw.

Affected Systems

The vulnerability affects the Splunk On-Call (VictorOps) application for Splunk, specifically all releases on Splunkbase with a version lower than 1.0.43. No other Splunk components are listed as affected.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate impact. The EPSS score is not available but the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a widely exploited risk at this time. The attack likely requires an internal user role that has read access to the app’s KV Store, i.e., a non‑admin Splunk user who can view the application data. As such, exploitation is possible in environments where such users exist and are granted read permissions to the KV Store. The absence of remote code execution or privilege escalation limits the severity, but the disclosed API key can still be leveraged to authenticate to downstream services controlled by that key.

Generated by OpenCVE AI on August 20, 2026 at 10:32 UTC.

Remediation

Vendor Solution

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.


Vendor Workaround

Turn off or remove the Splunk On-Call (VictorOps) app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade the Splunk On-Call (VictorOps) app to version 1.0.43 or later to eliminate the unmasked key storage.
  • If an upgrade is unavailable, disable or remove the Splunk On-Call (VictorOps) app entirely to prevent access to its KV Store.
  • Consider enforcing stricter permission boundaries so that only admin or power roles can read the application key store, mitigating the impact of any similar future issues.

Generated by OpenCVE AI on August 20, 2026 at 10:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Splunk on-call
CPEs cpe:2.3:a:splunk:on-call:*:*:*:*:*:*:*:*
Vendors & Products Splunk on-call

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Splunk
Splunk splunk On-call (victorops)
Vendors & Products Splunk
Splunk splunk On-call (victorops)

Wed, 19 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Description In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/administer-the-app-key-value-store/about-the-app-key-value-store) in the Splunk documentation.
Title Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Splunk On-call Splunk On-call (victorops)
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-08-20T15:26:30.983Z

Reserved: 2026-08-19T12:02:03.632Z

Link: CVE-2026-76405

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-19T22:17:27.297

Modified: 2026-08-24T18:25:16.063

Link: CVE-2026-76405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T10:45:03Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information