PatchSiren cyber security CVE debrief
CVE-2026-76286 Splunk CVE debrief
A Server-Side Request Forgery (SSRF) vulnerability exists in Splunk MCP Server versions below 1.2.1. An attacker could capture the authentication token of a user who runs a custom API tool and use it to access data and perform actions as that user. This could lead to unauthorized access to sensitive data and systems. The vulnerability requires a user with the mcp_tool_execute capability to run a custom API tool configured by another user. If the URL configured for the tool is controlled by an attacker, they could capture the token and use it to access data and perform actions as the user who ran the tool.
- Vendor
- Splunk
- Product
- Splunk MCP Server
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Splunk MCP Server deployments should assess exposure and verify the version of the server to prevent exploitation. This includes reviewing custom API tools and restricting access to prevent unauthorized users from running them. Additionally, defenders should monitor for suspicious activity related to custom API tools and user authentication. IT and security teams managing Splunk MCP Server should prioritize verifying the version,
Why it matters
Defenders should prioritize verifying the version of Splunk MCP Server and restricting access to custom API tools to prevent exploitation, as a Server-Side Request Forgery (SSRF) vulnerability exists in versions below 1.2.1.
- Potential unauthorized access to data and actions as a user who ran a custom API tool.
- Possible capture of user authentication tokens by an attacker controlling the URL configured for a custom API tool.
- Required verification of Splunk MCP Server version and access controls for custom API tools.
Technical summary
The vulnerability exists in Splunk MCP Server versions below 1.2.1, where a user who runs a custom API tool could have their authentication token sent to a URL configured for that tool. If another user controls that URL, they could capture the token and use it to access data and perform actions as the user who ran the tool. This requires a user with the mcp_tool_execute capability to run a custom API tool configured by another user. The vulnerability could lead to unauthorized access to sensitive data and systems. Successful exploitation requires a user who holds a role that contains the mcp_tool_execute capability to run a custom API tool configured by another user.
Defensive priority
Defenders should prioritize verifying the version of Splunk MCP Server and restricting access to custom API tools to prevent exploitation.
Recommended defensive actions
- Verify the version of Splunk MCP Server and upgrade to 1.2.1 or later if necessary.
- Restrict access to custom API tools to prevent unauthorized users from running them.
- Monitor for suspicious activity related to custom API tools and user authentication.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The CVE record and source item provide details on the vulnerability, but limited information is available on potential exploitation or affected systems. The Splunk documentation provides additional context on configuring the Splunk MCP Server and managing custom tools. However, the current information does not specify the exact scope of affected systems or the extent of potential exploitation. Defenders should verify the version of Splunk MCP Server and restrict access to custom API tools to prevent exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-76286 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-76286
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-76286 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-76286
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Server-Side Request Forgery (SSRF) through Custom API Tools in Splunk MCP Server
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/76xxx/CVE-2026-76286.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://advisory.splunk.com/advisories/SVD-2026-1004
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.