Splunk SOAR AD LDAP app <2.3.8 Debug Log Credential Exposure
CVE-2026-76375 Published on August 19, 2026
Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAR
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Weakness Type
Insertion of Sensitive Information into Log File
Information written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.
Products Associated with CVE-2026-76375
Want to know whenever a new CVE is published for Splunk? stack.watch will email you.
Affected Versions
AD LDAP app for Splunk SOAR:- Version 2.3 and below 2.3.8 is affected.