Junglewise Threat Intelligence

CVE-2026-76375: Splunk AD LDAP app information disclosure through environment data logging

CVE-2026-76375 · Severity: medium · CVSS 5 · Published 2026-08-19

Vendors: Splunk.

Executive brief

The AD LDAP app for Splunk SOAR is a connector that enables integration with Active Directory for user and group management. A vulnerability in versions below 2.3.8 allows authenticated users with action execution permissions to expose sensitive credentials and system configuration data by triggering debug logging that writes the entire connector process environment to a plaintext file. This could compromise API keys, passwords, and other secrets stored in environment variables.

Technical details

This is an information disclosure vulnerability (CWE-532) in the AD LDAP app for Splunk SOAR affecting versions below 2.3.8. The vulnerability occurs when a user with permission to execute actions invokes an action that causes the connector's full process environment to be dumped to a persistent debug log file in plaintext. The attack requires valid Splunk SOAR access with role-based permissions to run actions. An attacker can recover sensitive credentials and configuration data from the environment variables. The fix is available in version 2.3.8.

Affected products

  • Splunk AD LDAP app for Splunk SOAR Below 2.3.8

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fix available in version 2.3.8

References

Related threats