CVE-2026-76404

Published Aug 19, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-76404 is an unsafe deserialization vulnerability found in versions of the Splunk MCP Server app prior to 1.2.1. This flaw exists within the app's credential management component, which fails to validate the type of stored data during deserialization. An authenticated user possessing the "admin" Splunk role can exploit this vulnerability. By supplying or influencing crafted serialized data, the attacker can trigger the execution of arbitrary commands on the underlying operating system.

Description
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.
Source
psirt@cisco.com
NVD status
Analyzed
Products
model_context_protocol_server

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
6
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@cisco.com
CWE-502

Social media

Hype score
Not currently trending
  1. Splunk MCP Server などの 17 件の脆弱性が FIX:Across AI Toolkit と Kafka Apps の欠陥も修正 https://t.co/0WrS7115sW Splunk 各種アプリおよびアドオンに存在する、脆弱性 CVE-2026-76404/CVE-2026-76395/CVE-2026-76402

    @iototsecnews

    28 Aug 2026

    94 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-76404 Splunk MCP Server RCE 취약점 분석 및 패치 방법 https://t.co/AIM7R3EYbc

    @J_zjaan7946

    21 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. SplunkのMCP Serverアプリに深刻なリモートコード実行の脆弱性(CVE-2026-76404、CVSS 9.1)が発覚 CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) #DailyCyberSecurity (Aug 20) https://t.co/5jMPdoYyeT

    @foxbook

    21 Aug 2026

    245 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Warning: #Splunk fixed multiple vulnerabilities, including critical Remote Code Execution (#RCE) CVE-2026-76313 (CVSS 9.4) & CVE-2026-76404 (CVSS 9.1). https://t.co/89HvDtl3Rv #Patch #Patch #Patch

    @CCBalert

    20 Aug 2026

    272 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2026-76404: Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app Critical Vulnerability Alert! Splunk is affected by CVE-2026-76404. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/eMupfFzvud 🔍 Ident

    @zoomeye_team

    20 Aug 2026

    4587 Impressions

    23 Retweets

    59 Likes

    21 Bookmarks

    2 Replies

    1 Quote

  6. 🚨 SPLUNK SECURITY ALERT | CVE-2026-76404 | CyberRakshakLabs (https://t.co/2pavVsqatQ) 🔗A newly reported vulnerability, CVE-2026-76404, affects Splunk Apps and involves Stored Cross-Site Scripting (XSS). #CyberRakshakLabs #Splunk #CVE202676404 #CyberSecurity #XSS #SIEM #SO

    @vivekkumar86538

    20 Aug 2026

    4 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons. #Splunk #CVE #RemoteCodeExecution #RCE #MCPServer #Deserialization #InfoSec #PatchNow https://t.co/wEgwbMe22o

    @Daily_CyberSec

    20 Aug 2026

    307 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.