Executive brief
The Venafi connector for Splunk SOAR is used by security teams to manage digital certificates and encryption keys. In affected versions, users with permission to run actions can view keystore and private-key passwords in plain text in the user interface, exposing sensitive credentials used to protect critical cryptographic material.
Technical details
The vulnerability is a cleartext information disclosure (CWE-312) in the Venafi app for Splunk SOAR versions below 2.1.4. The get certificate action fails to mark the keystore_password and password parameters as sensitive, causing them to be displayed in plain text in the UI instead of being masked. An authenticated user with a role that permits running actions can invoke the get certificate action and expose keystore and private-key passwords. The fix is available in version 2.1.4 and later.
Affected products
- Splunk Venafi app for Splunk SOAR below 2.1.4
Timeline
- 2026-08-19: disclosed
- 2026-08-19: patched: Fixed in version 2.1.4