API Vulnerability in Splunk MCP Server Affects User Authentication Tokens
CVE-2026-76286
5.3MEDIUM
What is CVE-2026-76286?
In Splunk MCP Server versions earlier than 1.2.1, a security flaw exists where the Splunk platform authentication token of users utilizing a custom Application Programming Interface (API) tool may be inadvertently transmitted to a user-defined URL. If this URL is controlled by a malicious actor, they could intercept the authentication token, granting them unauthorized access to sensitive data and the ability to perform actions as the compromised user. Exploitation of this vulnerability requires that the affected user has the necessary role to execute custom API tools. Proper configuration and management of APIs are essential to mitigate these risks.
Affected Version(s)
Splunk MCP Server 1.2 < 1.2.1