Description
In Splunk MCP Server versions below 1.2.1, Splunk MCP Server could send the Splunk platform authentication token of a user who runs a custom Application Programming Interface (API) tool to the URL configured for that tool. If another user controls that URL, they could capture the token and use it to access data and perform actions as the user who ran the tool. Successful exploitation requires a user who holds a role that contains the mcp_tool_execute capability to run a custom API tool configured by another user. For more information see Configure the Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/configure-the-splunk-mcp-server) and Managing custom tools in Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/managing-custom-tools-in-splunk-mcp-server) in the Splunk documentation.
Published: 2026-10-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access through stolen authentication tokens
Action: Patch
AI Analysis

Impact

The vulnerability is a server‑side request forgery that occurs when Splunk MCP Server forwards a request containing the user’s Splunk authentication token to a URL configured for a custom API tool. Because the token is transmitted in the outbound request, an attacker who controls that destination can capture the token and reuse it to authenticate as the user who ran the tool. This allows the attacker to access data and perform actions on behalf of the compromised user. The weakness is identified as CWE‑918.

Affected Systems

Affected systems are installations of Splunk MCP Server running versions earlier than 1.2.1. The attack requires a user who holds a role with the mcp_tool_execute capability, making such users the primary risk agents. Any installation without the 1.2.1 hot‑fix remains vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and no EPSS score is available; the vulnerability is not listed in CISA's KEV catalog. The attack vector is an SSRF in a privileged user context, requiring that the attacker controls a URL target for a custom tool. Because the capability is role based, restricting the mcp_tool_execute permission to trusted personnel reduces risk. However, without patching or removing the vulnerable configuration, an attacker can capture authentication tokens and impersonate users.

Generated by OpenCVE AI on October 7, 2026 at 22:52 UTC.

Remediation

Vendor Solution

Upgrade Splunk MCP Server to version 1.2.1 or higher.


Vendor Workaround

Turn off or remove the Splunk MCP Server app. For more information see [Manage app and add-on objects](https://help.splunk.com/en/splunk-enterprise/administer/admin-manual/10.2/meet-splunk-apps/manage-app-and-add-on-objects) in the Splunk documentation.


OpenCVE Recommended Actions

  • Upgrade Splunk MCP Server to version 1.2.1 or higher
  • If an upgrade is not immediately possible, turn off or remove the Splunk MCP Server app
  • Restrict the mcp_tool_execute capability to trusted users only and review custom API tool configurations

Generated by OpenCVE AI on October 7, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
Description In Splunk MCP Server versions below 1.2.1, Splunk MCP Server could send the Splunk platform authentication token of a user who runs a custom Application Programming Interface (API) tool to the URL configured for that tool. If another user controls that URL, they could capture the token and use it to access data and perform actions as the user who ran the tool. Successful exploitation requires a user who holds a role that contains the mcp_tool_execute capability to run a custom API tool configured by another user. For more information see Configure the Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/configure-the-splunk-mcp-server) and Managing custom tools in Splunk MCP Server (https://help.splunk.com/en/splunk-enterprise/mcp-server-for-splunk-platform/1.2/managing-custom-tools-in-splunk-mcp-server) in the Splunk documentation.
Title Server-Side Request Forgery (SSRF) through Custom API Tools in Splunk MCP Server
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T20:46:40.297Z

Reserved: 2026-08-19T12:02:03.622Z

Link: CVE-2026-76286

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T21:17:20.387

Modified: 2026-10-07T21:17:20.387

Link: CVE-2026-76286

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T23:00:15Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)