Arbitrary Command Execution Vulnerability in Splunk MCP Server App
CVE-2026-76404

9.1CRITICAL

Key Information:

Vendor

Splunk

Vendor
CVE Published:
19 August 2026

What is CVE-2026-76404?

CVE-2026-76404 is an arbitrary command execution vulnerability found in the Splunk MCP Server app, specifically in versions prior to 1.2.1. Splunk is a software platform used for searching, monitoring, and analyzing machine-generated big data via a web-style interface. This vulnerability arises from insufficient input validation in the app's credential management component, allowing users with the "admin" role to execute arbitrary commands on the underlying operating system. If exploited, this flaw can lead to serious security breaches within the affected organization, as it undermines system integrity and control.

Potential Impact of CVE-2026-76404

  1. Unauthorized Access and Control: The primary risk associated with this vulnerability is the potential for unauthorized users to gain elevated privileges and execute arbitrary commands on the server, potentially leading to system compromise.

  2. Data Breaches: Exploitation could allow attackers to access sensitive data stored on the system, leading to possible data breaches that may have legal, financial, and reputational implications for the organization.

  3. Operational Disruption: Successful exploitation of this vulnerability could also disrupt business operations, as attackers may modify, delete, or corrupt critical application data and settings, resulting in service downtime and loss of functionality.

Affected Version(s)

Splunk MCP Server app 1.2 < 1.2.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kuniyoshi Noguchi (KuniNogu)
.