AI description
CVE-2026-76404 is an unsafe deserialization vulnerability found in versions of the Splunk MCP Server app prior to 1.2.1. This flaw exists within the app's credential management component, which fails to validate the type of stored data during deserialization. An authenticated user possessing the "admin" Splunk role can exploit this vulnerability. By supplying or influencing crafted serialized data, the attacker can trigger the execution of arbitrary commands on the underlying operating system.
- Description
- In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.
- Source
- psirt@cisco.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Primary
- Base score
- 9.1
- Impact score
- 6
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- psirt@cisco.com
- CWE-502
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
Warning: #Splunk fixed multiple vulnerabilities, including critical Remote Code Execution (#RCE) CVE-2026-76313 (CVSS 9.4) & CVE-2026-76404 (CVSS 9.1). https://t.co/89HvDtl3Rv #Patch #Patch #Patch
@CCBalert
20 Aug 2026
122 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
๐จ CVE-2026-76404: Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app Critical Vulnerability Alert! Splunk is affected by CVE-2026-76404. Full Vulnerability Details & Analysis at DarkEye: ๐ https://t.co/eMupfFzvud ๐ Ident
@zoomeye_team
20 Aug 2026
1369 Impressions
11 Retweets
32 Likes
11 Bookmarks
1 Reply
0 Quotes
Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons. #Splunk #CVE #RemoteCodeExecution #RCE #MCPServer #Deserialization #InfoSec #PatchNow https://t.co/wEgwbMe22o
@Daily_CyberSec
20 Aug 2026
305 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes