Executive brief
The Cisco Webex connector for Splunk SOAR is used by security teams to automate meeting scheduling and management tasks within their security operations. A flaw in versions before 2.2.1 allows users with action execution permissions to see meeting passwords displayed in cleartext in the user interface, rather than being masked like typical password fields. This could allow unauthorized disclosure of sensitive meeting credentials to users who should not have access to them.
Technical details
The vulnerability is a cleartext information disclosure (CWE-312) in the Cisco Webex app connector for Splunk SOAR versions below 2.2.1. The schedule meeting action's password parameter is not marked as a password field in the connector's action manifest, causing it to display in plaintext in the UI rather than being masked. Any user with the role permission to run actions can view the cleartext password when the schedule meeting action is invoked. The fix is available in version 2.2.1 and requires upgrading the affected connector.
Affected products
- Cisco Webex app for Splunk SOAR below 2.2.1
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in version 2.2.1