Information Disclosure in Azure AD Graph App for Splunk SOAR
CVE-2026-76377
4.3MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-76377?
In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, the temporary password parameter is returned in plaintext within the user interface when a user with appropriate permissions invokes the reset password action. This oversight allows unauthorized individuals to view sensitive information, posing a risk for information disclosure. The vulnerability arises from the failure to properly mask the temp_password parameter, which could lead to significant security concerns for affected users.
Affected Version(s)
Azure AD Graph app for Splunk SOAR 2.5 < 2.5.3