Impact
The vulnerability is a server‑side request forgery that occurs when Splunk MCP Server forwards a request containing the user’s Splunk authentication token to a URL configured for a custom API tool. Because the token is transmitted in the outbound request, an attacker who controls that destination can capture the token and reuse it to authenticate as the user who ran the tool. This allows the attacker to access data and perform actions on behalf of the compromised user. The weakness is identified as CWE‑918.
Affected Systems
Affected systems are installations of Splunk MCP Server running versions earlier than 1.2.1. The attack requires a user who holds a role with the mcp_tool_execute capability, making such users the primary risk agents. Any installation without the 1.2.1 hot‑fix remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and no EPSS score is available; the vulnerability is not listed in CISA's KEV catalog. The attack vector is an SSRF in a privileged user context, requiring that the attacker controls a URL target for a custom tool. Because the capability is role based, restricting the mcp_tool_execute permission to trusted personnel reduces risk. However, without patching or removing the vulnerable configuration, an attacker can capture authentication tokens and impersonate users.
OpenCVE Enrichment