目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-76375— AD LDAP app for Splunk SOAR 环境数据泄露漏洞

CVSS 5.0 · Medium EPSS 0.21% · P12

Possible ATT&CK Techniques 1AI

T1530 · Data from Cloud Storage

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
SplunkAD LDAP app for Splunk SOAR2.3< 2.3.8affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-76375の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
Information Disclosure through Environment Data Logging in AD LDAP app for Splunk SOAR
ソース: CVE Program / CVE List V5
脆弱性説明
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials by invoking an action that causes the full connector process environment to be written to a persistent debug log file in plaintext. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
ソース: CVE Program / CVE List V5
脆弱性タイプ
通过日志文件的信息暴露
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
SplunkAD LDAP app for Splunk SOAR 2.3 ~ 2.3.8 -

II. CVE-2026-76375の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-76375のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-76375 厂商安全公告 (1)

Same Patch Batch · Splunk · 2026-08-19 · 110 CVEs total

CVE-2026-763119.4 CRITICALImproper Access Control in Embedded Report Dispatch Archives in Splunk Enterprise
CVE-2026-763109.4 CRITICALImproper Access Control through Embedded Report REST API Requests in Splunk Enterprise
CVE-2026-763129.4 CRITICALImproper Access Control through Embedded Reports in Splunk Enterprise
CVE-2026-764049.1 CRITICALRemote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server
CVE-2026-763358.8 HIGHRemote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise
CVE-2026-763508.8 HIGHImproper Privilege Management through PDF Attachments for Email Alert Actions in Splunk En
CVE-2026-763898.8 HIGHServer-Side Request Forgery (SSRF) through the REST API in Cisco Talos Intelligence for En
CVE-2026-763518.8 HIGHServer-Side Request Forgery (SSRF) through the Report Notification REST API in Splunk Secu
CVE-2026-763198.8 HIGHRemote Code Execution (RCE) through Federated Search in Splunk Enterprise
CVE-2026-763168.8 HIGHStored SPL Injection through Deployment Server Broker Registration in Splunk Enterprise
CVE-2026-763958.8 HIGHRemote Code Execution (RCE) through Deserialization of Untrusted Data in the Model Loading
CVE-2026-762538.8 HIGHPrivilege Escalation through Scheduled Search Alert Action Configuration in Splunk Enterpr
CVE-2026-763528.8 HIGHImproper Authorization through the REST API in Splunk Enterprise
CVE-2026-763158.8 HIGHCode Injection through Splunk Web Manager Configuration in Splunk Enterprise
CVE-2026-762598.8 HIGHImproper Privilege Management on the Management Port in Splunk Enterprise for Windows
CVE-2026-763178.8 HIGHPath Traversal through the Lookup Configuration REST API in Splunk Enterprise
CVE-2026-763148.8 HIGHRemote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk Enterprise
CVE-2026-763138.8 HIGHRemote Code Execution (RCE) through the REST API in Splunk Enterprise
CVE-2026-763948.3 HIGHMissing Authorization in Container and Connection Management through the REST API in Splun
CVE-2026-763918.3 HIGHImproper Privilege Management through Agent Run History in Splunk AI Toolkit

Showing 20 of 110 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-76375へのコメント

まだコメントはありません


コメントを残す