What is CVE-2026-76374?
In Splunk SOAR's AD LDAP app versions below 2.3.8, a user with run action permissions can cause sensitive Active Directory response data to be written to a persistent debug log file. This flaw risks exposing confidential AD data. Upgrading the app to version 2.3.8 is recommended to remediate the issue.
Azərbaycanca: Splunk SOAR üçün AD LDAP tətbiqinin 2.3.8-dən əvvəlki versiyalarında, hərəkət icra etmək icazəsi olan istifadəçi debug loqlarına həssas Active Directory məlumatlarının yazılmasına səbəb ola bilər. Bu boşluq məxfi AD cavablarının ifşa riski yaradır. Tətbiqi 2.3.8 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Splunk
FAQ2
What sensitive data can be written to debug logs in Splunk SOAR's AD LDAP app?
In versions of Splunk SOAR's AD LDAP app below 2.3.8, sensitive Active Directory response data can be written to a persistent debug log file.
What is recommended to fix the CVE-2026-76374 vulnerability?
Upgrading the AD LDAP app to version 2.3.8 is recommended to remediate the CVE-2026-76374 issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.