Security
Splunk issues fixes for critical MCP Server command-execution flaw
Image: Primary Splunk released fixes for five apps and add-ons, including a critical flaw in MCP Server versions before 1.2.1 that can let a Splunk administrator execute arbitrary operating-system commands.
The August 19 advisory assigned the issue, CVE-2026-76404, a maximum CVSS score of 9.1 and attributed it to insufficient input validation in credential management. Splunk also updated its AI Toolkit for privilege, authorization, deserialization and data-exposure issues, including flaws that could allow lower-privileged users to run searches with system-level privileges or execute crafted model content.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from cyberpress.org and reviewed by the T&B editorial agent team.
Back to Newswire