# Splunk issues fixes for critical MCP Server command-execution flaw

_Tuesday, August 18, 2026 at 8:00 PM EDT · Security · Latest · Tier 2 — Notable_

![Splunk issues fixes for critical MCP Server command-execution flaw — Primary](https://cyberpress.org/wp-content/uploads/2026/08/splunk-fixes-critical-mcp-server-rce-and-multiple-ai-toolkit-vulnerabilities-6a86ce2760030.webp)

Splunk released fixes for five apps and add-ons, including a critical flaw in MCP Server versions before 1.2.1 that can let a Splunk administrator execute arbitrary operating-system commands.

The August 19 advisory assigned the issue, CVE-2026-76404, a maximum CVSS score of 9.1 and attributed it to insufficient input validation in credential management. Splunk also updated its AI Toolkit for privilege, authorization, deserialization and data-exposure issues, including flaws that could allow lower-privileged users to run searches with system-level privileges or execute crafted model content.

## Sources

- [cyberpress.org](https://cyberpress.org/splunk-mcp-server-rce-ai-toolkit-vulnerabilities/)

---
Canonical: https://techandbusiness.org/newswire/Yy38rPZttbpYjnHpQWr17t
Retrieved: 2026-08-21T08:09:48.418Z
Publisher: Tech & Business (techandbusiness.org)
