AI description
CVE-2026-76404 is an unsafe deserialization vulnerability found in versions of the Splunk MCP Server app prior to 1.2.1. This flaw exists within the app's credential management component, which fails to validate the type of stored data during deserialization. An authenticated user possessing the "admin" Splunk role can exploit this vulnerability. By supplying or influencing crafted serialized data, the attacker can trigger the execution of arbitrary commands on the underlying operating system.
- Description
- In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.
- Source
- psirt@cisco.com
- NVD status
- Analyzed
- Products
- model_context_protocol_server
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@cisco.com
- CWE-502
- Hype score
- Not currently trending
Splunk MCP Server などの 17 件の脆弱性が FIX:Across AI Toolkit と Kafka Apps の欠陥も修正 https://t.co/0WrS7115sW Splunk 各種アプリおよびアドオンに存在する、脆弱性 CVE-2026-76404/CVE-2026-76395/CVE-2026-76402
@iototsecnews
28 Aug 2026
94 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-76404 Splunk MCP Server RCE 취약점 분석 및 패치 방법 https://t.co/AIM7R3EYbc
@J_zjaan7946
21 Aug 2026
6 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SplunkのMCP Serverアプリに深刻なリモートコード実行の脆弱性(CVE-2026-76404、CVSS 9.1)が発覚 CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) #DailyCyberSecurity (Aug 20) https://t.co/5jMPdoYyeT
@foxbook
21 Aug 2026
245 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: #Splunk fixed multiple vulnerabilities, including critical Remote Code Execution (#RCE) CVE-2026-76313 (CVSS 9.4) & CVE-2026-76404 (CVSS 9.1). https://t.co/89HvDtl3Rv #Patch #Patch #Patch
@CCBalert
20 Aug 2026
272 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-76404: Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app Critical Vulnerability Alert! Splunk is affected by CVE-2026-76404. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://t.co/eMupfFzvud 🔍 Ident
@zoomeye_team
20 Aug 2026
4587 Impressions
23 Retweets
59 Likes
21 Bookmarks
2 Replies
1 Quote
🚨 SPLUNK SECURITY ALERT | CVE-2026-76404 | CyberRakshakLabs (https://t.co/2pavVsqatQ) 🔗A newly reported vulnerability, CVE-2026-76404, affects Splunk Apps and involves Stored Cross-Site Scripting (XSS). #CyberRakshakLabs #Splunk #CVE202676404 #CyberSecurity #XSS #SIEM #SO
@vivekkumar86538
20 Aug 2026
4 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons. #Splunk #CVE #RemoteCodeExecution #RCE #MCPServer #Deserialization #InfoSec #PatchNow https://t.co/wEgwbMe22o
@Daily_CyberSec
20 Aug 2026
307 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:splunk:model_context_protocol_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "D34DCE3E-FC83-4D4F-91BF-A2AD23B38838",
"versionEndExcluding": "1.2.1",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]