Information Disclosure in RSA SecurID Authentication Manager for Splunk SOAR
CVE-2026-76383
4.3MEDIUM
Key Information:
- Vendor
Splunk
- Vendor
- CVE Published:
- 19 August 2026
What is CVE-2026-76383?
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, an elevated privilege user can inadvertently disclose sensitive token serial numbers. This exposure occurs when invoking actions such as enable token or revoke token, as the token_serial parameter is displayed in cleartext on the user interface. The vulnerability arises from the failure to mask the token_serial as a secure parameter, allowing sensitive information to be viewed by users who have permissions to execute these actions.
Affected Version(s)
RSA SecurID Authentication Manager app for Splunk SOAR 1.0 < 1.0.5