CVE-2026-76374
Received Received - Intake

Information Disclosure in Splunk SOAR AD LDAP App

Vulnerability report for CVE-2026-76374, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
splunk ad_ldap_app to 2.3.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user with permission to run actions could cause sensitive Active Directory response data to be written to a debug log file by triggering write operations through the app.

Detection Guidance

Check Splunk SOAR logs for the AD LDAP app version below 2.3.8. Look for persistent debug log files containing sensitive Active Directory response data. Review user actions triggering write operations in the app.

Impact Analysis

An attacker with the right permissions could access sensitive Active Directory data stored in debug logs, potentially leading to unauthorized information disclosure.

Compliance Impact

This vulnerability could lead to unauthorized exposure of personal or sensitive data, potentially violating GDPR or HIPAA compliance requirements for data protection and confidentiality.

Mitigation Strategies

Upgrade the AD LDAP app for Splunk SOAR to version 2.3.8 or higher. Restrict user roles with permission to run actions. Review and remove any sensitive data from debug log files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76374. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart