CVE-2026-76404Patch(splunk / model_context_protocol_server)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk model_context_protocol_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which deserializes stored data without checking whether the content is of the expected type.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • model_context_protocol_server

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 5 mentions (2026-08-20); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
model_context_protocol_server

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-08-20: 5Mentions · 2026-08-21: 1Mentions · 2026-08-26: 1Mentions · 2026-08-28: 1Patch / Workaround · 2026-08-20: 4Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-20: 5Technical Details · 2026-08-21: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-28: 108-2008-2108-2608-28
Signal classification2 categories
Patch
562.5%
Disclosure
337.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-205
Disclosure1Patch4
2026-08-211
Disclosure1
2026-08-261
Disclosure1
2026-08-281
Patch1
Full discourse8 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-76404: Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app Critical Vulnerability Alert! Splunk is affected by CVE-2026-76404. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-76404 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-76404" Search Dork: Splunk Exposure: 1.5m instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=U3BsdW5r&t=all&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260820 #Infosec #CyberSecurity #ZoomEye #DarkEye 🚀 ZoomEye continues to expand its AI ecosystem. Today we're introducing WebMCP support, enabling compatible AI agents to discover and invoke ZoomEye tools directly from the website. Explore our AI ecosystem: 1⃣ WebMCP 2⃣ MCP Server →(http://github.com/zoomeye-ai/mcp…) 3⃣ AI Skills →(http://ai.trusttools.cn/skills/zoomeye…) Building an AI-native cybersecurity platform. #Infosec #CyberSecurity #ZoomEye #DarkEye

    Post summary

    The post announces the critical RCE vulnerability CVE-2026-76404 affecting Splunk MCP Server, linking to detailed analysis and scanning resources but providing no PoC, exploit, or patch information.

    226164236.7K
    12.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    Splunk patches CVE-2026-76404, a critical remote code execution flaw in the MCP Server app, plus 16 more bugs across its apps and add-ons. #Splunk #CVE #RemoteCodeExecution #RCE #MCPServer #Deserialization #InfoSec #PatchNow https://securityonline.info/splunk-apps-cve-2026-76404/

    Post summary

    Splunk released a patch for CVE-2026-76404, a critical RCE flaw in the MCP Server app, and also addressed 16 additional bugs across its apps and add‑ons.

    10010388
    12.9K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Splunk fixed multiple vulnerabilities, including critical Remote Code Execution (#RCE) CVE-2026-76313 (CVSS 9.4) & CVE-2026-76404 (CVSS 9.1). https://advisory.splunk.com/ #Patch #Patch #Patch

    Post summary

    Splunk has released patches for CVE‑2026‑76313 and CVE‑2026‑76404, both critical remote code execution vulnerabilities with CVSS scores of 9.4 and 9.1.

    01000303
    7.2K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Splunk MCP Server などの 17 件の脆弱性が FIX:Across AI Toolkit と Kafka Apps の欠陥も修正 https://iototsecnews.jp/2026/08/20/splunk-patches-critical-mcp-server-rce-and-16-other-security-flaws-across-ai-toolkit-kafka-apps/ Splunk 各種アプリおよびアドオンに存在する、脆弱性 CVE-2026-76404/CVE-2026-76395/CVE-2026-76402 などの動向と対策を解説する記事です。この件の背景にあるのは、デシリアライズ処理の制御不備やアクセス制御の検証不足です。この不備により、リモートからの任意コード実行/認証クレデンシャルの流出/検索所有権限の改ざんといった影響が生じる恐れがあります。対応策として、指定バージョンへの迅速な更新/管理用 API へのアクセス制限/ロール割り当ての再評価が求められます。 #Across AI Toolkit #CVE202676389 #CVE202676391 #CVE202676394 #CVE202676395 #CVE202676396 #CVE202676397 #CVE202676399 #CVE202676402 #CVE202676403 #CVE202676404 #KafkaApps #MCPServer #Splunk #Vulnerability

    Post summary

    The article announces that Splunk has released patches for 17 vulnerabilities, including CVE‑2026‑76404, CVE‑2026‑76395, and CVE‑2026‑76402, and advises updates plus API access limits to mitigate deserialization and privilege‑escalation issues.

    00000174
    511 followersView on X
  • UWillC@uwillc
    Disclosure

    Enterprise MCP just crossed a threshold: the first critical CVE in a vendor-backed MCP server. CVE-2026-76404. CVSS 9.1. Splunk MCP Server app, versions below 1.2.1. The flaw: the app's credential management component deserializes stored data without checking what it actually is. A user holding the admin Splunk role can execute arbitrary commands on the underlying operating system. To be precise: this is not unauthenticated. You need admin. The severity is not the entry bar. It is the location. MCP is the connector layer. It is where agents touch production logs, run queries, and feed incident response workflows. A deserialization bug there is a very old software failure showing up in a very new place. Docker surveyed 800 plus developers this year: 85 percent of teams know MCP, 40 percent call security the number one blocker for scaling agents. The 40 percent were not being paranoid. They were early. The fix is out: 1.2.1. What is your bar for letting an integration layer this young touch production data?

    Post summary

    The post announces CVE‑2026‑76404, a deserialization RCE in Splunk MCP Server with a CVSS score of 9.1 affecting versions below 1.2.1, requiring admin privileges, and notes that patch 1.2.1 has been released.

    0000080
    496 followersView on X
  • キタきつね@foxbook
    Disclosure

    SplunkのMCP Serverアプリに深刻なリモートコード実行の脆弱性(CVE-2026-76404、CVSS 9.1)が発覚 CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) #DailyCyberSecurity (Aug 20) https://securityonline.info/splunk-apps-cve-2026-76404/

    Post summary

    A critical remote code execution vulnerability (CVE-2026-76404) with CVSS 9.1 has been disclosed for Splunk's MCP Server App, but no exploit details or mitigation steps are provided.

    00000277
    4.9K followersView on X
  • CyberOGZ@cyberogz
    Patch

    New RCE in Splunk MCP app (CVE-2026-76404). Via untrusted data deserialization. If you run it, patch now.

    Post summary

    Splunk MCP app contains a new RCE vulnerability (CVE-2026-76404) triggered by untrusted data deserialization; users are urged to apply the available patch immediately.

    0000092
    18 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Splunk MCP Server app unsafe deserialization → OS command execution (CVE-2026-76404) A user holding the admin Splunk role can execute arbitrary commands on the underlying OS, because the app's credential management component deserializes stored data without validating that the content is of the expected type. Scope-changed — code runs outside the Splunk app boundary, at host level. 👉Affected: Splunk MCP Server app < 1.2.1 | Upgrade to 1.2.1

    Post summary

    Critical vulnerability (CVE-2026-76404) in Splunk MCP Server app allows admin users to execute arbitrary OS commands via unsafe deserialization; upgrade to 1.2.1 to mitigate.

    0000094
    292 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunkmodel_context_protocol_server---

Explore more