PT-2026-78831 · Splunk · Splunk Mcp Server
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk MCP Server app versions prior to 1.2.1
Description
Users with the admin Splunk role can execute arbitrary commands on the underlying operating system. This occurs due to missing input validation within the credential management component, which performs deserialization—the process of converting stored data back into an object—without verifying if the content matches the expected type.
Recommendations
Update Splunk MCP Server app to version 1.2.1 or later.
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Mcp Server