Executive brief
The AWS IAM app for Splunk SOAR, a security automation tool used to manage AWS account access, fails to mask sensitive AWS credentials in the user interface when users run actions. An attacker with permissions to run actions could view and capture these credentials in plaintext, allowing unauthorized access to AWS accounts and the resources they control.
Technical details
The vulnerability exists in the AWS IAM app for Splunk SOAR due to improper handling of sensitive credential parameters in action execution. When a user invokes an action that accepts AWS credentials as a parameter, the application fails to mark the parameter as a password field, causing credentials to be displayed in plaintext in the user interface rather than being masked. This is a CWE-312 (Cleartext Storage of Sensitive Information) vulnerability. An authenticated user with permission to run actions can view exposed credentials without requiring additional privileges. The fix is to upgrade to version 2.1.9 or later, which properly marks credential parameters as password fields.
Affected products
- Splunk AWS IAM app for Splunk SOAR below 2.1.9
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in version 2.1.9