What is CVE-2026-76373?
This vulnerability in Splunk SOAR's AD LDAP app versions below 2.3.8 allows a user with 'run actions' permission to inject crafted input into Active Directory queries, enabling enumeration of objects (accounts, groups, OUs) and reading of sensitive attributes. Upgrading the AD LDAP app to version 2.3.8 or later is recommended to mitigate the issue.
Azərbaycanca: Bu zəiflik Splunk SOAR-ın AD LDAP tətbiqinin 2.3.8-dən aşağı versiyalarında "run actions" icazəsi olan istifadəçiyə xüsusi hazırlanmış giriş vasitəsilə Active Directory sorğularında obyektləri (hesablar, qruplar) sadalamağa və həssas atributları oxumağa imkan verir. Təsirə məruz qalmamaq üçün AD LDAP tətbiqini ən az 2.3.8 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: Splunk
FAQ2
What permission does an attacker need to exploit CVE-2026-76373 in Splunk SOAR?
The attacker needs to have 'run actions' permission.
Upgrading the AD LDAP app to which version mitigates CVE-2026-76373?
Upgrading the AD LDAP app to version 2.3.8 or later is recommended to mitigate the issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.