CVE-2026-76404: Unsafe Deserialization in Splunk MCP Server
A trust-boundary failure in the Splunk MCP Server app's credential-management path allowed stored data to reach unsafe deserialization, enabling an administrator to execute commands on the underlying operating system.
- Product:
- Splunk MCP Server app
- CVE:
- CVE-2026-76404