Junglewise Threat Intelligence

CVE-2026-76377: Splunk Azure AD Graph app information disclosure in action parameters

CVE-2026-76377 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Vendors: Splunk.

Executive brief

The Azure AD Graph app for Splunk SOAR is a connector that allows administrators to manage Azure Active Directory accounts and permissions. In affected versions, a user with permission to run actions can see password reset values displayed in plaintext in the UI instead of being masked, exposing sensitive credentials. This could lead to password compromise if displayed on shared screens or recorded logs.

Technical details

The vulnerability is an information disclosure flaw (CWE-312) in the Azure AD Graph app for Splunk SOAR versions below 2.5.3. The reset password action's temp_password parameter is not marked as a password field, causing it to be displayed in cleartext in the user interface rather than being masked. The attack vector is network-based and requires the attacker to hold a role with permission to execute actions in Splunk SOAR. An authenticated user can invoke the reset password action and view the temporary password value directly on the screen. The vulnerability is fixed in version 2.5.3 and later.

Affected products

  • Splunk Azure AD Graph app for Splunk SOAR below 2.5.3

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 2.5.3

References