CVE-2026-76383
Received Received - Intake

Information Disclosure in RSA SecurID Authentication Manager for Splunk SOAR

Vulnerability report for CVE-2026-76383, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rsa_security securid_authentication_manager to 1.0.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR. A user with permission to run actions can expose a sensitive token serial by using the enable token or revoke token action. The token_serial parameter is displayed in cleartext in the UI because the app does not mask it as a password field.

Detection Guidance

Check if you are using RSA SecurID Authentication Manager app for Splunk SOAR version below 1.0.5. Inspect UI actions for enable token or revoke token to see if token_serial appears in cleartext.

Impact Analysis

An attacker with access to the UI could view token serials, potentially leading to unauthorized token management or further exploitation. This could compromise the integrity of authentication tokens used for secure access.

Compliance Impact

This vulnerability exposes sensitive token serial numbers in cleartext, which could lead to unauthorized access to authentication tokens. For GDPR, this may violate principles of data protection and confidentiality. For HIPAA, it could compromise protected health information if tokens are linked to user accounts handling such data.

Mitigation Strategies

Upgrade the RSA SecurID Authentication Manager app for Splunk SOAR to version 1.0.5 or later to address the token_serial exposure issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76383. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart