Splunk App Soar: 18 Vulnerabilities Disclosed, Exposing Passwords and System Data
A batch of 18 vulnerabilities affecting Splunk App Soar and its integrated applications were disclosed on August 19, 2026, with many leading to sensitive data exposure.

Key findings
- 18 vulnerabilities disclosed for Splunk App Soar on August 19, 2026.
- Multiple vulnerabilities involve cleartext exposure of passwords and sensitive credentials in various apps.
- Core Splunk SOAR platform issues include SQL injection, unauthorized access, and session token recovery.
- One high-severity vulnerability (CVE-2026-76362) impacts CyberArk integration.
- Patches are available in Splunk SOAR versions below 8.6.0 and specific app versions.
On August 19, 2026, a batch of 18 vulnerabilities was disclosed for Splunk App Soar, affecting various applications and the core platform. These vulnerabilities, primarily rated Medium with some Low and one High, largely stem from improper handling of sensitive information such as passwords and credentials, as well as insufficient access controls. The disclosures highlight a common theme of sensitive data being exposed in cleartext or logs, and unauthorized access to data and system functions.
Several vulnerabilities relate to specific apps integrated with Splunk SOAR, where actions designed to manage sensitive data inadvertently expose it. For instance, CVE-2026-76386 in the Zoom app and CVE-2026-76379 in the Cisco Webex app allow users to expose meeting passwords. Similarly, CVE-2026-76385 in the Venafi app and CVE-2026-76377 in the Azure AD Graph app can lead to the exposure of keystore and temporary passwords, respectively. The Phantom app (CVE-2026-76382) and MS Graph for Active Directory app (CVE-2026-76371) also suffer from similar password exposure issues.
Other vulnerabilities impact the core Splunk SOAR platform and its interaction with other systems. CVE-2026-76375 and CVE-2026-76374 in the AD LDAP app involve sensitive data being written to debug logs or allowing enumeration of Active Directory objects. A more severe SQL injection vulnerability, CVE-2026-76363, allows an "Automation Engineer" role to execute arbitrary SQL statements, potentially leading to full database compromise. Additionally, CVE-2026-76362, a high-severity vulnerability, could allow an unauthenticated user to access or modify data exchanged between Splunk SOAR and a CyberArk REST server if network traffic can be observed or altered.
The core platform also exhibits issues with tenant access control and session token recovery. CVE-2026-76370 allows authenticated users with restricted tenant access to view unauthorized tenant names and identifiers. CVE-2026-76366 enables users to recover session tokens via REST API filtering on playbook runs, compromising all data accessible to the affected user. Low-severity issues include CVE-2026-76371, where unauthorized changes to file lists might be possible, and CVE-2026-76368, allowing unauthorized viewing of playbook repository metadata. CVE-2026-76361, another low-severity finding, permits users to probe internal network reachability. Finally, CVE-2026-76358 involves a path traversal vulnerability during app installation, allowing files to be written outside the intended directory.
The majority of these vulnerabilities have been addressed in Splunk SOAR versions below 3.2.2 for the Zoom app, 2.1.4 for Venafi, 3.8.5 for Phantom, 1.5.2 for MS Graph for Active Directory, 2.2.1 for Cisco Webex, 2.5.3 for Azure AD Graph, 2.1.9 for AWS IAM, 2.3.8 for AD LDAP, and 2.1.15 for FireAMP. Core Splunk SOAR platform vulnerabilities are fixed in versions below 8.6.0. Users are strongly advised to update to the patched versions to mitigate these security risks.
This extensive batch of disclosures underscores the importance of regularly reviewing and updating Splunk SOAR and its integrated applications. The common theme of sensitive data exposure and insufficient access controls highlights a need for vigilant security practices, including prompt patching and careful management of user roles and permissions. Users should prioritize updating to the latest versions to protect against these identified weaknesses.