Skip to content
Threat Feed
high advisory

Arbitrary Command Execution in Splunk MCP Server App via Insecure Deserialization

Splunk MCP Server app versions below 1.2.1 are vulnerable to remote code execution due to improper deserialization of untrusted data in the credential management component, allowing users with administrative privileges to execute arbitrary commands.

CVE search metadata

CVE search record: CVE-2026-76404. Severity: critical. CVSS: 9.1. KEV: no. Product: Splunk MCP Server app. Brief: Arbitrary Command Execution in Splunk MCP Server App via Insecure Deserialization. Brief link: https://feed.craftedsignal.io/briefs/2026-08-splunk-mcp-deserialization/

Splunk MCP Server app versions prior to 1.2.1 contain a critical security vulnerability, tracked as CVE-2026-76404, stemming from insecure deserialization of untrusted data. The vulnerability resides in the application's credential management component, which fails to perform adequate input validation before deserializing stored data. An attacker who has successfully compromised or holds an account with 'admin' level privileges within the Splunk environment can exploit this flaw to execute arbitrary commands on the underlying host operating system. This issue represents a significant risk for organizations where administrative access is shared or delegated, as the vulnerability effectively allows for privilege escalation from a legitimate Splunk administrative role to full host-level control.

Impact

Successful exploitation allows an authenticated administrative user to achieve full command execution on the host running the Splunk MCP Server. This could lead to complete system compromise, unauthorized access to sensitive data, and potential lateral movement within the enterprise network. Organizations utilizing Splunk MCP Server versions below 1.2.1 should prioritize upgrading to the patched version immediately to mitigate this risk.

Recommendation

  • Upgrade the Splunk MCP Server app to version 1.2.1 or higher immediately to address CVE-2026-76404.
  • Audit logs for suspicious command execution originating from the Splunk MCP Server service account or associated service processes.
  • Review administrative user access to the Splunk environment to ensure compliance with the principle of least privilege, minimizing the number of users who hold the 'admin' role required to trigger this vulnerability.

Immediate actions

Upgrade Splunk MCP Server app to version 1.2.1 or higher.

IT Operations 48h

Mitigations

Restrict Splunk administrative roles to authorized personnel only.

immediate IT Operations

CVE-2026-76404