Input Injection Vulnerability in AD LDAP App for Splunk SOAR
CVE-2026-76373

5.4MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76373?

In versions prior to 2.3.8 of the AD LDAP app for Splunk SOAR, a user with the ability to execute actions could exploit input injection vulnerabilities within Active Directory queries. This could lead to unauthorized enumeration of Active Directory objects such as user accounts and groups, as well as the exposure of sensitive attributes from various directory objects. Additionally, it could allow the manipulation of account modification actions, potentially redirecting them to unintended targets. Users are advised to upgrade to the latest version to mitigate these risks.

Affected Version(s)

AD LDAP app for Splunk SOAR 2.3 < 2.3.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gabriel Nitu, Splunk
.