AUGUST 26, 2026
Live Feed
Back to database
Case File

CVE-2026-76404

CRITICAL · CVSS 9.1 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-08-25

CyberRota Analysis

AI-Generated

The vulnerability in Splunk MCP Server app versions prior to 1.2.1 allows users with the "admin" role to execute arbitrary commands on the underlying operating system due to inadequate input validation in the credential management component. This critical flaw poses a significant risk of unauthorized access and system compromise. Organizations using affected versions should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-76404
Severity
CRITICAL
CVSS
9.1
EPSS
0.56%

Original NVD Description

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

Related CVEs

Other vulnerabilities affecting the same vendor(s)