Information Disclosure in MS Graph for Active Directory App for Splunk SOAR
CVE-2026-76381
4.3MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-76381?
In versions prior to 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a security flaw allows users with permission to execute actions to inadvertently expose sensitive password information. This occurs when the reset password action is invoked, revealing the temporary password in cleartext due to the app not properly masking this parameter in the user interface. This oversight highlights the necessity for appropriate handling of sensitive data within application interfaces.
Affected Version(s)
MS Graph for Active Directory app for Splunk SOAR 1.5 < 1.5.2