CVE-2026-76374
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Summary
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could cause sensitive Active Directory response data to be written to a persistent debug log file by triggering write operations through the app. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Splunk | AD LDAP app for Splunk SOAR | 2.3 < 2.3.8 | affected |
Weaknesses
- CWE-532: Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
Workarounds
Turn off or remove the AD LDAP app for Splunk SOAR. For more information see Add and configure apps and assets to provide actions in Splunk SOAR in the Splunk documentation. Note: Turning off the app stops all actions configured through it from running.
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.