CVE-2026-76404: Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Splunk MCP Server appto a version that resolves this vulnerability.Fixed in 1.2.1
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs a Splunk account with the admin role. The issue affects the credential management component of the Splunk MCP Server app.
Which versions are affected?
Splunk MCP Server app versions below 1.2.1 are affected. Upgrading to version 1.2.1 or later addresses the affected version range described.
What access does successful exploitation provide?
A user with the admin Splunk role can execute arbitrary commands on the underlying operating system. This can affect confidentiality, integrity, and availability beyond the Splunk application.