API Vulnerability in Splunk MCP Server Affects User Authentication Tokens
CVE-2026-76286

5.3MEDIUM

Key Information:

Vendor

Splunk

Vendor
CVE Published:
7 October 2026

What is CVE-2026-76286?

In Splunk MCP Server versions earlier than 1.2.1, a security flaw exists where the Splunk platform authentication token of users utilizing a custom Application Programming Interface (API) tool may be inadvertently transmitted to a user-defined URL. If this URL is controlled by a malicious actor, they could intercept the authentication token, granting them unauthorized access to sensitive data and the ability to perform actions as the compromised user. Exploitation of this vulnerability requires that the affected user has the necessary role to execute custom API tools. Proper configuration and management of APIs are essential to mitigate these risks.

Affected Version(s)

Splunk MCP Server 1.2 < 1.2.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuniyoshi Noguchi (KuniNogu)
.