Information Disclosure Vulnerability in Cisco Webex App for Splunk SOAR
CVE-2026-76379

4.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76379?

In versions prior to 2.2.1 of the Cisco Webex app for Splunk SOAR, users with permission to execute actions may inadvertently reveal sensitive meeting passwords. This occurs when the 'schedule meeting' action's password parameter is displayed in plain text instead of being masked, leading to potential exposure of confidential information. The app does not properly categorize this parameter as a password, making it visible in the user interface. This issue underscores the need for careful handling of sensitive data within applications.

Affected Version(s)

Cisco Webex app for Splunk SOAR 2.2 < 2.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.