Sceawere

Vulnerability Detail

CVE-2026-76405UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Splunk On-Call API Key Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
19h ago
Vendor
Splunk
Product
Splunk On-Call (VictorOps)
Attack Type
The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/administer-the-app-key-value-store/about-the-app-key-value-store) in the Splunk documentation.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-19T22:17:27.297Z",
  "pubdate": "2026-08-19T22:17:27.297Z",
  "executiveSummary": "An information disclosure vulnerability exists in the Splunk On-Call (VictorOps) app for Splunkbase in versions below 1.0.43. The vulnerability allows unprivileged users lacking the 'admin' or 'power' Splunk roles to read sensitive credential data from the application's storage layer. The primary impact is the unauthorized exposure of a partially masked Application Programming Interface (API) key stored within the App Key Value Store (KV Store). This security flaw poses significant risk implications regarding credential compromise, potentially allowing unauthorized actors to interact with downstream integrated services utilizing the exposed API key. Exploitation requires read access to the KV Store collection and targets environments running vulnerable versions of the Splunk On-Call (VictorOps) app.",
  "technicalDetails": "The root cause of the vulnerability stems from improper data sanitization and overly permissive access controls implemented by the Splunk On-Call (VictorOps) app prior to version 1.0.43. Specifically, the application fails to fully mask the Application Programming Interface (API) key before persisting the sensitive string into an App Key Value Store (KV Store) collection. Although standard security practices dictate strict segregation of sensitive configuration parameters, the KV Store collection containing the API key was configured or exposed in a manner that permitted read access to users who do not possess elevated privileges such as the 'admin' or 'power' Splunk roles.\nThe attack flow begins when an authenticated user with standard, unprivileged access queries the vulnerable App Key Value Store (KV Store) collection associated with the Splunk On-Call (VictorOps) app. Because the application fails to sufficiently sanitize or fully mask the stored Application Programming Interface (API) key during the write or storage phase, the raw or insufficiently masked credential data is returned in the query response. The vulnerable component is the data handling and storage routine responsible for persisting configuration secrets within the KV Store.\nExploitation prerequisites require the attacker to maintain authenticated access to the Splunk instance and possess the ability to query the specific KV Store collection utilized by the application. Network exposure is constrained by the accessibility of the Splunk web interface or REST API endpoints enforcing the underlying access controls. Upon retrieving the exposed Application Programming Interface (API) key, an attacker can analyze the string to reconstruct or directly leverage the credential against external integrated systems, facilitating post-exploitation activities such as unauthorized data access or manipulation within the connected VictorOps infrastructure."
}
CVE-2026-76405: Splunk On-Call API Key Information Disclosure (MEDIUM Severity, CVSS: 4.3) - Sceawere