Information Disclosure Vulnerability in Splunk Attack Analyzer Connector
CVE-2026-76384

4.3MEDIUM

What is CVE-2026-76384?

In versions prior to 2.2.1 of the Splunk Attack Analyzer Connector, a user with appropriate permissions could inadvertently expose sensitive archive passwords. This occurs when using the 'detonate file' or 'detonate url' actions, as the archive_password parameter is displayed in cleartext within the user interface. The parameter lacks masking, leading to potential unauthorized access to sensitive data. It is crucial for users to update to version 2.2.1 or later to mitigate this risk.

Affected Version(s)

Splunk Attack Analyzer Connector for Splunk SOAR 2.2 < 2.2.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.