PT-2026-107708 · Splunk · Splunk Mcp Server

·

CVE-2026-76286

·

Published

2026-10-07

·

Updated

2026-10-08

CVSS v3.1

5.3

Medium

VectorAV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Splunk MCP Server versions prior to 1.2.1
Description Splunk MCP Server contains a Server-Side Request Forgery (SSRF) flaw where the platform authentication token of a user running a custom API tool may be sent to the URL configured for that tool. If an attacker controls the destination URL, they can capture the token to access data and perform actions on behalf of the affected user. Exploitation requires a user with the mcp tool execute capability to execute a custom API tool configured by another user.
Recommendations Update Splunk MCP Server to version 1.2.1 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76286

Affected Products

Splunk Mcp Server