What is CVE-2026-76375?
This vulnerability exists in versions below 2.3.8 of the AD LDAP app for Splunk SOAR. A user with permissions to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. Upgrading to version 2.3.8 or later is recommended.
Azərbaycanca: Bu zəiflik Splunk SOAR-un AD LDAP tətbiqində (2.3.8-dən aşağı versiyalarda) aşkarlanıb. Müəyyən icazələrə malik istifadəçi, debug log faylına proses mühitinin (environment) düz mətn şəklində yazılmasına səbəb olan bir əməliyyat işlədərək həssas etimadnamələri ifşa edə bilər. Tətbiqi ən azı 2.3.8 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200; shared vendor: Splunk
FAQ2
In which Splunk SOAR app was CVE-2026-76375 found, and which versions are affected?
The vulnerability exists in versions below 2.3.8 of the AD LDAP app for Splunk SOAR.
How can CVE-2026-76375 lead to the exposure of sensitive credentials?
A user with permissions to run actions could expose credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.