PT-2026-107708 · Splunk · Splunk Mcp Server
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Splunk MCP Server versions prior to 1.2.1
Description
Splunk MCP Server contains a Server-Side Request Forgery (SSRF) flaw where the platform authentication token of a user running a custom API tool may be sent to the URL configured for that tool. If an attacker controls the destination URL, they can capture the token to access data and perform actions on behalf of the affected user. Exploitation requires a user with the
mcp tool execute capability to execute a custom API tool configured by another user.Recommendations
Update Splunk MCP Server to version 1.2.1 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Mcp Server