CVE-2026-76385
Received Received - Intake

Information Disclosure in Venafi Splunk SOAR App

Vulnerability report for CVE-2026-76385, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-19

Last updated on: 2026-08-19

Assigner: Cisco Systems, Inc.

Description

In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked and are shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameters as passwords. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-19
Last Modified
2026-08-19
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
venafi venafi_app 2.1.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-312 The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user with permission to run actions could expose keystore and private-key passwords by using the get certificate action. The passwords are displayed in cleartext in the UI because the app does not mask the keystore_password and password parameters.

Detection Guidance

Check Splunk SOAR app version for Venafi app. If version is below 2.1.4, the system is vulnerable. Look for exposed keystore and private-key passwords in UI logs when the get certificate action is run.

Impact Analysis

An attacker with access to the UI could view sensitive passwords, potentially leading to unauthorized access to encrypted data or systems. This could result in data breaches or further exploitation of the environment.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations may face compliance violations, legal penalties, and reputational damage.

Mitigation Strategies

Upgrade the Venafi app for Splunk SOAR to version 2.1.4 or higher to ensure sensitive parameters are masked. Review user roles with action permissions to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76385. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart