CVE-2026-76404

Published Aug 19, 2026

Last updated 2 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-76404 is an unsafe deserialization vulnerability found in versions of the Splunk MCP Server app prior to 1.2.1. This flaw exists within the app's credential management component, which fails to validate the type of stored data during deserialization. An authenticated user possessing the "admin" Splunk role can exploit this vulnerability. By supplying or influencing crafted serialized data, the attacker can trigger the execution of arbitrary commands on the underlying operating system.

Description
In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.
Source
psirt@cisco.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
9.1
Impact score
6
Exploitability score
2.3
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

psirt@cisco.com
CWE-502

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

4

References

Sources include official advisories and independent security research.