Vibe Coding
Splunk Patches a CVSS 9.1 Deserialization RCE in Its MCP Server App
CVE-2026-76404, published 2026-08-19, is an unsafe-deserialization remote code execution flaw in the Splunk MCP Server app before version 1.2.1, in the app's credential-management component. An authenticated user with the Splunk `admin` role can supply crafted serialized data and execute arbitrary OS commands on the host. It landed as part of a batch of 17 Splunk fixes, and it is a reminder that enterprise MCP servers inherit the full blast radius of the system they wrap, not just the tool surface they expose.
Source
↳ Follow the thread