CVE-2026-76404: Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app

Published Aug 19, 2026
·
Updated

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

Affected Software

1 affected component
Splunk MCP Server app<1.2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Splunk MCP Server app to a version that resolves this vulnerability.

    Fixed in 1.2.1

Event History

Aug 19, 2026
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An attacker needs a Splunk account with the admin role. The issue affects the credential management component of the Splunk MCP Server app.

2

Which versions are affected?

Splunk MCP Server app versions below 1.2.1 are affected. Upgrading to version 1.2.1 or later addresses the affected version range described.

3

What access does successful exploitation provide?

A user with the admin Splunk role can execute arbitrary commands on the underlying operating system. This can affect confidentiality, integrity, and availability beyond the Splunk application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203