CVE-2026-76383
Information Disclosure through Action Parameters in RSA SecurID Authentication Manager app for Splunk SOAR
In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial parameter is not masked and is shown in cleartext in the user interface. The information disclosure is possible because the app does not mark the affected action parameter as a password. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
| CWE | CWE-312 |
| Vendor | splunk |
| Product | rsa securid authentication manager app for splunk soar |
| Published | Aug 19, 2026 |
Get instant alerts for splunk rsa securid authentication manager app for splunk soar
Be the first to know when new medium vulnerabilities affecting splunk rsa securid authentication manager app for splunk soar are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N