Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-76386

CVE-2026-76386: Zoom App for Splunk SOAR Disclosure Flaw

CVE-2026-76386 is an information disclosure vulnerability in the Zoom app for Splunk SOAR that exposes meeting passwords in cleartext. This article covers the technical details, affected versions, and mitigation steps.

Updated:

CVE-2026-76386 Overview

CVE-2026-76386 is an information disclosure vulnerability in the Zoom app for Splunk SOAR (Security Orchestration, Automation, and Response) in versions below 3.2.2. The flaw allows a user with a role permitted to run actions to view meeting and personal meeting ID (PMI) passwords in cleartext. The password and pmi_password parameters used by the create meeting, update meeting, and update user settings actions are not masked in the user interface. This exposure occurs because the app does not flag these parameters as password fields. The issue maps to CWE-312: Cleartext Storage of Sensitive Information.

Critical Impact

Authenticated Splunk SOAR users with action-run privileges can read Zoom meeting passwords and PMI passwords in cleartext, enabling unauthorized access to Zoom meetings.

Affected Products

  • Zoom app for Splunk SOAR versions below 3.2.2
  • Splunk SOAR deployments integrating the Zoom app for meeting automation
  • Environments using the create meeting, update meeting, or update user settings actions

Discovery Timeline

  • 2026-08-19 - CVE-2026-76386 published to NVD
  • 2026-08-20 - Last updated in NVD database

Technical Details for CVE-2026-76386

Vulnerability Analysis

The Zoom app for Splunk SOAR exposes several actions that accept sensitive password parameters. Specifically, the create meeting, update meeting, and update user settings actions accept password and pmi_password values used to protect Zoom meetings and personal meeting rooms. Because these parameters are not declared as password-type inputs, the Splunk SOAR user interface renders them in cleartext rather than masking them. Any authenticated SOAR user with a role that permits running actions can therefore observe the values submitted to and stored by the app.

The consequence is unauthorized disclosure of meeting credentials to users who should not necessarily hold them. An attacker who obtains these passwords can join meetings, potentially eavesdrop on confidential discussions, or impersonate legitimate participants. Confidentiality is affected while integrity and availability of the SOAR platform itself are not.

Root Cause

The root cause is a missing parameter attribute in the app's action definition. Splunk SOAR provides a mechanism to mark input fields as passwords so that the UI masks them and treats them as sensitive. The Zoom app, in versions below 3.2.2, does not apply this attribute to password and pmi_password, resulting in cleartext handling in the interface.

Attack Vector

Exploitation requires an authenticated SOAR account with permission to run actions. The attacker navigates to the affected Zoom actions and reads the parameter values as they are displayed by the SOAR UI. No network exploit chain or specialized tooling is required. See Splunk Security Advisory SVD-2026-0806 for vendor details.

Detection Methods for CVE-2026-76386

Indicators of Compromise

  • Splunk SOAR audit logs showing users invoking the Zoom app create meeting, update meeting, or update user settings actions outside of documented playbooks.
  • Unexpected Zoom meeting join events from accounts or IP addresses not associated with the meeting owner.
  • Zoom account activity indicating changes to personal meeting ID passwords without a corresponding administrative change ticket.

Detection Strategies

  • Review Splunk SOAR role assignments and identify all users who currently hold action-run permissions on the Zoom app.
  • Correlate SOAR action invocations against expected playbook execution to surface manual or exploratory runs of the affected Zoom actions.
  • Query Zoom admin logs for meeting joins that do not correlate to scheduled attendee lists during the vulnerable period.

Monitoring Recommendations

  • Enable and forward Splunk SOAR audit logs to a centralized SIEM for retention and correlation.
  • Alert on any modification of the Zoom app configuration or invocation of update user settings by non-administrator roles.
  • Monitor Zoom tenant logs for anomalous meeting access patterns following any confirmed exposure of password or pmi_password values.

How to Mitigate CVE-2026-76386

Immediate Actions Required

  • Upgrade the Zoom app for Splunk SOAR to version 3.2.2 or later.
  • Rotate all Zoom meeting passwords and personal meeting ID passwords that were configured through the affected actions.
  • Audit and reduce the set of SOAR users granted permission to run actions on the Zoom app.

Patch Information

Splunk has released Zoom app for Splunk SOAR version 3.2.2, which marks the password and pmi_password parameters as passwords so they are masked in the user interface. Refer to Splunk Security Advisory SVD-2026-0806 for the official fix and upgrade instructions.

Workarounds

  • Restrict the role-based access control (RBAC) permissions for the Zoom app so only trusted administrators can run the affected actions until the upgrade is applied.
  • Avoid setting or updating Zoom meeting passwords through the affected SOAR actions; configure them directly in the Zoom administration console instead.
  • Rotate any potentially exposed meeting credentials on a regular cadence until the patched version is deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.