Junglewise Threat Intelligence

CVE-2026-76373: Splunk SOAR AD LDAP app LDAP injection in action parameters

CVE-2026-76373 · Severity: medium · CVSS 5.4 · Published 2026-08-19

Vendors: Splunk.

Executive brief

The AD LDAP connector for Splunk SOAR allows users with permission to run automated actions to inject malicious input into Active Directory queries. An attacker can enumerate AD objects (accounts, groups, organizational units), extract sensitive attributes from arbitrary directory entries, and redirect account modification actions to unintended targets. This exposure could lead to unauthorized directory enumeration and account tampering.

Technical details

The vulnerability is a filter injection flaw (CWE-90) in the AD LDAP app for Splunk SOAR versions below 2.3.8. A user with the role permission to run actions can craft malicious input to inject LDAP filters into Active Directory queries. The attack requires the attacker to have role-based access to execute actions within Splunk SOAR. By injecting crafted filters, an attacker can enumerate directory objects including user accounts, security groups, and organizational units; read sensitive attributes from arbitrary objects; and redirect modify-account actions to unintended targets. The vulnerability is fixed in version 2.3.8 and later.

Affected products

  • Splunk SOAR AD LDAP app below 2.3.8

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fix version 2.3.8 released

References