CVE-2026-76373
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read sensitive attributes from arbitrary directory objects, and redirect account modification actions to unintended objects. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.18%
- CWE
- CWE-90
- Published
- 2026-08-19
- Last modified
- 2026-08-20
Affected products
- Splunk AD LDAP app for Splunk SOAR
Weakness type
Related vulnerabilities
- CVE-2026-80055 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-78579 — Improper Input Sanitization in Okta Access Gateway LDAP Datastore Filter Interpolation
- CVE-2026-81205 — LDAP / Active Directory Integration - Moderately critical - Information Disclosure - SA-CONTRIB-2026-115
- CVE-2026-75020 — Apache APISIX: ldap-auth plugin cross-subtree identity impersonation
- CVE-2026-19271 — Blind LDAP Injection in Sign-In Endpoint in TÜBİTAK BİLGEM's Liderahenk
- CVE-2026-19930 — Dolibarr User Cloning card.php ldap injection
- CVE-2026-74241 — Quay: ldap referral filter injection in quay external ldap authentication
- CVE-2026-16071 — Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary