Junglewise Threat Intelligence

CVE-2026-76378: Cisco Secure Malware Analytics app for Splunk SOAR information disclosure in action parameters

CVE-2026-76378 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Vendors: Cisco.

Executive brief

The Cisco Secure Malware Analytics app for Splunk SOAR is a plugin that enables malware analysis capabilities within Splunk's security orchestration platform. A flaw in versions before 2.4.5 allows users with action-execution permissions to view sensitive passwords in cleartext within the user interface, as the sample_password parameter is not properly masked. This could expose credentials used for detonating malware samples, compromising security operations and potentially enabling unauthorized access to analysis systems.

Technical details

The vulnerability is an information disclosure flaw (CWE-312) in the Cisco Secure Malware Analytics connector for Splunk SOAR. The detonate file action's sample_password parameter is not marked as a sensitive field and is therefore displayed in plaintext in the UI rather than being masked. An authenticated user with permissions to run actions can invoke the detonate file action and view the exposed password in cleartext. The vulnerability requires network access to Splunk SOAR and an authenticated session with action execution privileges. Upgrading to version 2.4.5 or later remediates the issue by properly marking the parameter as a password field.

Affected products

  • Cisco Secure Malware Analytics app for Splunk SOAR Below 2.4.5

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 2.4.5

References