Arbitrary Command Execution Vulnerability in Splunk MCP Server App
CVE-2026-76404
9.1CRITICAL
What is CVE-2026-76404?
A vulnerability exists in the Splunk MCP Server app versions prior to 1.2.1, where an administrator can execute arbitrary commands on the underlying operating system due to insufficient input validation in the app's credential management system. This flaw allows the deserialization of stored data without verifying its content type, potentially leading to unauthorized access and control over the system.
Affected Version(s)
Splunk MCP Server app 1.2 < 1.2.1