Information Disclosure in RSA SecurID Authentication Manager for Splunk SOAR
CVE-2026-76383

4.3MEDIUM

What is CVE-2026-76383?

In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, an elevated privilege user can inadvertently disclose sensitive token serial numbers. This exposure occurs when invoking actions such as enable token or revoke token, as the token_serial parameter is displayed in cleartext on the user interface. The vulnerability arises from the failure to mask the token_serial as a secure parameter, allowing sensitive information to be viewed by users who have permissions to execute these actions.

Affected Version(s)

RSA SecurID Authentication Manager app for Splunk SOAR 1.0 < 1.0.5

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.