Information Disclosure in MS Graph for Active Directory App for Splunk SOAR
CVE-2026-76381

4.3MEDIUM

What is CVE-2026-76381?

In versions prior to 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a security flaw allows users with permission to execute actions to inadvertently expose sensitive password information. This occurs when the reset password action is invoked, revealing the temporary password in cleartext due to the app not properly masking this parameter in the user interface. This oversight highlights the necessity for appropriate handling of sensitive data within application interfaces.

Affected Version(s)

MS Graph for Active Directory app for Splunk SOAR 1.5 < 1.5.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.