Junglewise Threat Intelligence

CVE-2026-76380: CrowdStrike OAuth API app for Splunk SOAR information disclosure in action parameters

CVE-2026-76380 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Executive brief

The CrowdStrike OAuth API connector for Splunk SOAR is used by security teams to integrate CrowdStrike threat intelligence into their incident response workflows. In affected versions, a user with permission to run actions could view sensitive passwords in the user interface, as the document_password parameter is displayed in cleartext instead of being masked. This could expose credentials used for file and URL detonation analysis.

Technical details

This is an information disclosure vulnerability (CWE-312) caused by the CrowdStrike OAuth API app for Splunk SOAR failing to mark the document_password parameter as a password field in the action manifest. The detonate file and detonate url actions expose this parameter in cleartext in the user interface, accessible to any user with a role permission to run actions. No authentication bypass or network exploit is required; the vulnerability relies on direct UI access by an already-authorized user. The affected versions are below 5.1.3; patched versions mask sensitive parameters properly.

Affected products

  • CrowdStrike OAuth API app for Splunk SOAR below 5.1.3

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Version 5.1.3 available

References