CVE-2026-76405 PUBLISHED

Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app

Assigner: cisco
Reserved: 19.08.2026 Published: 19.08.2026 Updated: 19.08.2026

In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/9.2/administer-the-app-key-value-store/about-the-app-key-value-store) in the Splunk documentation.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor Splunk
Product Splunk On-Call (VictorOps)
Versions
  • affected from 1.0 to 1.0.43 (excl.)

Workarounds

Turn off or remove the Splunk On-Call (VictorOps) app. For more information see Manage app and add-on objects in the Splunk documentation.

Solutions

Upgrade each affected Splunk app or add-on to the applicable fixed version listed in Product Status.

Credits

  • Gabriel Nitu, Splunk reporter

References

Problem Types

  • The application stores sensitive information in cleartext within a resource that might be accessible to another control sphere. cwe