CVE-2026-76405

Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app

Severity
Medium 4.3
CVSS 3.1
Remote, needs privileges or user interaction what this means
Exploited
Not listed
EPSS
0.002
7.6th percentile
Discovered by
Not disclosed
Published
Aug 19, 2026
Assigned by cisco

Description

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/administer-the-app-key-value-store/about-the-app-key-value-store) in the Splunk documentation.

Weakness: CWE-312

Affected products

Vendor Product Category Matched by
Cisco Splunk Apps & Add-ons SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Splunk · Splunk On-Call (VictorOps)

Credit

Gabriel Nitu, Splunk

Vendor remediation

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.

Something wrong here?