Junglewise Threat Intelligence

CVE-2026-76386: Splunk Zoom app for SOAR password disclosure in action parameters

CVE-2026-76386 · Severity: medium · CVSS 4.3 · Published 2026-08-19

Vendors: Splunk.

Executive brief

The Zoom connector app for Splunk SOAR fails to mask sensitive passwords when displaying action parameters in the user interface. A user with permission to run actions could view meeting and personal meeting ID passwords in cleartext, potentially exposing credentials used to secure Zoom meetings and access controls. This impacts organizations relying on Splunk SOAR for security orchestration if they use the Zoom app with untrusted users who have action-execution privileges.

Technical details

The vulnerability is an information disclosure flaw (CWE-312) in the Zoom app for Splunk SOAR versions below 3.2.2. The affected action parameters (password and pmi_password) are not marked as password-type fields in the app's action manifest, causing them to be displayed in cleartext in the UI when users invoke create meeting, update meeting, or update user settings actions. Any authenticated user with a role that has permission to run actions can view these credentials on screen. The fix is available in version 3.2.2 and later. No authentication bypass or network-based exploitation is required beyond existing action-execution privileges.

Affected products

  • Splunk Zoom app for SOAR below 3.2.2

Timeline

  • 2026-08-19: disclosed
  • 2026-08-19: patched: fix version 3.2.2 released

References