Junglewise Threat Intelligence

CVE-2026-76381: Splunk MS Graph for Active Directory app information disclosure through unmasked password parameter

CVE-2026-76381 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Vendors: Splunk.

Executive brief

The MS Graph for Active Directory app for Splunk SOAR is a connector that manages Active Directory operations within security orchestration workflows. In versions before 1.5.2, a user with permission to run actions can view a temporary password in cleartext in the user interface during password reset operations, because the application fails to mask sensitive password fields. An attacker with appropriate role permissions could capture and misuse exposed credentials.

Technical details

This is an information disclosure vulnerability (CWE-312) affecting the MS Graph for Active Directory app for Splunk SOAR versions below 1.5.2. The root cause is that the reset password action's temp_password parameter is not marked as a password field in the action manifest, causing the application to display it in cleartext in the user interface rather than masking it. An attacker must hold a role with permission to run actions in Splunk SOAR to view the exposed password. The vulnerability requires no network attack vector—it is exposed through the Splunk SOAR UI. The fix is to upgrade to version 1.5.2 or later.

Affected products

  • Splunk MS Graph for Active Directory app for Splunk SOAR below 1.5.2

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fixed in version 1.5.2

References