CVE-2026-76375
Received Received - Intake

Credentials Exposure in Splunk SOAR AD LDAP App

Vulnerability report for CVE-2026-76375, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
splunk ad_ldap_app to 2.3.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in versions below 2.3.8 of the AD LDAP app for Splunk SOAR. A user with permission to run actions can expose sensitive credentials by triggering an action that writes the full connector process environment, including credentials, to a debug log file in plaintext.

Detection Guidance

Check Splunk SOAR logs for the AD LDAP app version below 2.3.8. Look for persistent debug log files containing plaintext credentials. Verify if any user with action permissions has invoked actions recently.

Impact Analysis

An attacker with access to the debug log file could retrieve exposed credentials, potentially leading to unauthorized access to systems or data protected by those credentials. This could result in data breaches or further exploitation within the environment.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage due to potential data exposure.

Mitigation Strategies

Upgrade the AD LDAP app for Splunk SOAR to version 2.3.8 or higher immediately. Review and restrict roles with action permissions to minimize exposure. Inspect and secure any debug log files containing sensitive data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76375. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart