Junglewise Threat Intelligence

CVE-2026-76383: RSA SecurID Authentication Manager information disclosure in action parameters

CVE-2026-76383 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Vendors: Splunk.

Executive brief

The RSA SecurID Authentication Manager app for Splunk SOAR exposes sensitive token serial numbers in cleartext when users run token management actions. A user with permission to execute actions can see these normally-protected identifiers in the web interface, potentially compromising token management security and enabling unauthorized token manipulation. The issue affects deployments running versions below 1.0.5.

Technical details

This is an information disclosure vulnerability (CWE-312) in the RSA SecurID Authentication Manager connector for Splunk SOAR versions below 1.0.5. The enable token and revoke token actions fail to mask the token_serial parameter, displaying it in cleartext in the user interface instead of treating it as a password field. The vulnerability requires authentication (the attacker must hold a role with permission to run actions) and network access to Splunk SOAR. An attacker can extract sensitive token identifiers that could facilitate further unauthorized actions against the RSA authentication infrastructure. The fix is to upgrade to version 1.0.5 or later.

Affected products

  • Splunk RSA SecurID Authentication Manager app for Splunk SOAR below 1.0.5

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fix version 1.0.5 released

References