CVE-2026-76286: Server-Side Request Forgery (SSRF) through Custom API Tools in Splunk MCP Server
In Splunk MCP Server versions below 1.2.1, Splunk MCP Server could send the Splunk platform authentication token of a user who runs a custom Application Programming Interface (API) tool to the URL configured for that tool. If another user controls that URL, they could capture the token and use it to access data and perform actions as the user who ran the tool. Successful exploitation requires a user who holds a role that contains the mcptoolexecute capability to run a custom API tool configured by another user. For more information see Configure the Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/configure-the-splunk-mcp-server) and Managing custom tools in Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/managing-custom-tools-in-splunk-mcp-server) in the Splunk documentation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk MCP Serverto a version that resolves this vulnerability.Fixed in 1.2.1
Event History
Frequently Asked Questions
Which deployments are affected?
Splunk MCP Server versions below 1.2.1 are affected. Version 1.2.1 and later are not included in the affected version range.
What conditions are required for exploitation?
A user with a role containing the mcp_tool_execute capability must run a custom API tool configured by another user. That other user must control the URL configured for the tool in order to capture the executing user's Splunk platform authentication token.
What can be done before upgrading?
Do not allow users to run custom API tools configured by untrusted users or pointing to URLs they do not trust. Limit the mcp_tool_execute capability to users who need it.