Product
Splunk MCP Server app versions below 1.2.1 are vulnerable to remote code execution due to improper deserialization of untrusted data in the credential management component, allowing users with administrative privileges to execute arbitrary commands.