Sensitive Information Exposure in AWS IAM App for Splunk SOAR
CVE-2026-76376

4.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76376?

The AWS IAM app for Splunk SOAR versions prior to 2.1.9 has a flaw that allows users with appropriate permissions to inadvertently expose sensitive AWS credentials through a cleartext credentials parameter. This is because the relevant action parameter is not designated as a password within the user interface, leading to potential data leaks during action executions. Properly marking such parameters is crucial to prevent unauthorized disclosure of sensitive information.

Affected Version(s)

AWS IAM app for Splunk SOAR 2.1 < 2.1.9

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.