Skip to content

CVE-2026-76404

Splunk MCP Server app deserialization flaw lets admin users run OS commands (CVE-2026-76404)

Critical 9.1 Vendor: Cisco Published

Splunk MCP Server app versions 1.2 through before 1.2.1 contain a critical deserialization vulnerability (CVSS 9.1). An attacker with the admin Splunk role can execute arbitrary OS commands. Install version 1.2.1 to fix the issue.

What happened

CVE-2026-76404 is a deserialization of untrusted data flaw (CWE-502) in the Splunk MCP Server app's credential management component. The app deserializes stored data without validating that the content is of the expected type. A user who holds the admin Splunk role could exploit this to execute arbitrary commands on the underlying operating system.

The issue is reachable over the network. It requires high privileges but no user interaction, and successful exploitation can affect the confidentiality, integrity and availability of the broader system. The CVSS 3.1 base score is 9.1 (critical).

At the time of writing, the available data records no CISA KEV entry and no exploitation or public disclosure.

Who is affected

The affected product is the Splunk MCP Server app. The listed affected range is version 1.2 up to but not including 1.2.1. Organisations should treat this as relevant where the app is installed in a Splunk environment and where admin-role accounts are provisioned. If you run a version in that range, assume you are affected until the update is applied.

What to do now

  1. Update to Splunk MCP Server app 1.2.1, the fixed release listed for CVE-2026-76404.
  2. If you cannot update immediately, reduce the number of accounts holding the admin Splunk role and review the network reachability of the Splunk deployment.
  3. Monitor the Splunk host for unexpected processes or commands, particularly activity linked to the MCP Server app's credential management component.

No workaround is listed in the available advisory data; the fixed version is the primary remediation.

How to detect it

Successful exploitation would result in arbitrary commands running on the underlying OS. Look for unexpected processes, command shells or scripts launched by the Splunk host account, particularly after activity in the MCP Server app's credential management component.

Beyond the patch

Beyond applying the update, this CVE is a reminder that deserialisation and authentication flaws are usually found by a penetration test that covers credential handling before they become incidents — Implementation & Assessment Services reviews exactly that. If an admin account is misused to run OS commands, the process and account activity is the kind of trail EDR and SIEM monitoring can detect, which is the focus of our Managed Detection & Response (MDR) service.

Affected and fixed versions

ProductAffectedFixed in
Splunk MCP Server app1.2 – < 1.2.11.2.1

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.