Junglewise Threat Intelligence

CVE-2026-76384: Splunk Attack Analyzer Connector information disclosure in action parameters

CVE-2026-76384 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Vendors: Splunk.

Executive brief

The Splunk Attack Analyzer Connector for Splunk SOAR failed to mask a sensitive archive password parameter in its detonation actions, allowing authorized users to view the password in plaintext through the user interface. This could enable unauthorized access to protected archives or credential compromise when users inadvertently share screenshots or logs containing the exposed information.

Technical details

CVE-2026-76384 is an information disclosure vulnerability (CWE-312) in the Splunk Attack Analyzer Connector affecting versions below 2.2.1. The "detonate file" and "detonate url" actions expose the archive_password parameter in cleartext in the UI because the parameter was not marked as a password field in the app's action manifest. The vulnerability requires the attacker to hold a role with permission to run actions in Splunk SOAR. An attacker with such permissions can invoke these actions and view the plaintext password, potentially leading to unauthorized access or lateral movement. The fix is available in version 2.2.1.

Affected products

  • Splunk Attack Analyzer Connector for Splunk SOAR below 2.2.1

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: Fix version 2.2.1 available

References