Junglewise Threat Intelligence

CVE-2026-76374: Splunk AD LDAP app information disclosure through debug logging

CVE-2026-76374 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Vendors: Splunk.

Executive brief

The AD LDAP app for Splunk SOAR is used to integrate Active Directory authentication and directory services into security orchestration workflows. A vulnerability allows users with permission to run actions to trigger the logging of sensitive Active Directory response data to persistent debug log files, potentially exposing credentials and directory information to unauthorized access.

Technical details

The vulnerability is classified as CWE-532 (Insertion of Sensitive Information into Log File). In AD LDAP app versions below 2.3.8, the application writes sensitive Active Directory response data directly to persistent debug log files without sanitization. An authenticated user holding a role with permission to run actions can trigger this data logging by executing write operations through the app. The attack requires authentication and action execution privileges but no user interaction or elevated access. An attacker can extract sensitive data including credentials and directory information from the log files. The fix is available in version 2.3.8 and later.

Affected products

  • Splunk AD LDAP app for Splunk SOAR below 2.3.8

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 2.3.8

References

Related threats