CVE-2026-76373: Filter Injection through Action Parameters in AD LDAP app for Splunk SOAR
In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an Active Directory query to enumerate Active Directory objects, including accounts, groups, and organizational units, read sensitive attributes from arbitrary directory objects, and redirect account modification actions to unintended objects. For more information see Run an action in Splunk SOAR (https://help.splunk.com/en/splunk-soar/soar-on-premises/use-splunk-soar-on-premises/8.6.0/use-the-command-line-interface-to-perform-tasks-in-splunk-soar-on-premises/run-an-action-in-splunk-soar-on-premises).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk SOAR AD LDAP appto a version that resolves this vulnerability.Fixed in 2.3.8 - Upgrade
Upgrade
Splunk SOARto a version that resolves this vulnerability.Fixed in 8.6.0
Event History
Frequently Asked Questions
Who can exploit this issue?
A user with a Splunk SOAR role that permits running actions can exploit it. No additional user interaction is required.
What access could an attacker gain or alter?
An attacker could enumerate Active Directory accounts, groups, and organizational units, read sensitive attributes from arbitrary directory objects, and cause account modification actions to target unintended objects.
Which deployments are affected?
The issue affects versions of the AD LDAP app for Splunk SOAR below 2.3.8.