Home Cyber Security News Splunk Fixes Critical MCP Server RCE and Multiple AI Toolkit Vulnerabilities

Splunk Fixes Critical MCP Server RCE and Multiple AI Toolkit Vulnerabilities

0

Splunk has released security fixes for five apps and add-ons, addressing a critical remote code execution flaw in its MCP Server app and a wide range of privilege-management, authorization, deserialization, and data-exposure weaknesses in the Splunk AI Toolkit.

The August 19 security hardening advisory, tracked as SVD-2026-0808, carries a maximum CVSS v3.1 score of 9.1. The most severe issue, CVE-2026-76404, affects Splunk MCP Server app versions earlier than 1.2.1.

The vulnerability allows a user with the Splunk “admin” role to execute arbitrary operating-system commands. Splunk attributed the flaw to insufficient input validation in the credential-management component, which deserializes stored data without ensuring it is the expected type.

Splunk Fixes Multiple Vulnerabilities

Tracked as CWE-502, or deserialization of untrusted data, the issue can enable malicious serialized content to trigger command execution on the host running Splunk.

The vulnerability has a CVSS vector of AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, reflecting that exploitation requires administrative Splunk access but could result in complete compromise.

Splunk AI Toolkit received the largest group of fixes. CVE-2026-76391 and CVE-2026-76394, both rated 8.3, could allow low-privileged users to run searches with system-level privileges or manage containers and connection data via insufficiently protected REST API handlers.

CVE-2026-76395, rated 8.8, permits users with the “power” role to execute arbitrary code by loading a crafted model file containing sparse matrix data with embedded pickle content.

The AI Toolkit flaws also include scheduled-search permission problems, predictable container-service credentials, race conditions during model uploads, and unauthorized access to experiment history.

CVE-2026-76399 allows a “power” user to modify app-provided scheduled searches that run under the search owner’s permissions. This could expose data beyond the user’s intended access level and allow unauthorized changes to Splunk search operations.

Splunk addressed the AI Toolkit vulnerabilities in version 6.0.0 and later, while CVE-2026-76398 and CVE-2026-76399 require version 6.0.1. Administrators should note that disabling the AI Toolkit stops AI Toolkit SPL commands and model operations.

It may also disrupt Splunk Apps for Data Science and Deep Learning deployments, as well as custom search commands that depend on AI Toolkit models and APIs.

CVEAffected ProductVulnerability Type
CVE-2026-76389Cisco Talos Intelligence for Enterprise Security CloudSSRF through REST API
CVE-2026-76390Cisco Talos Intelligence for Enterprise Security CloudInformation disclosure via unauthenticated OpenAPI specification access
CVE-2026-76391Splunk AI ToolkitImproper privilege management through Agent Run History
CVE-2026-76392Splunk AI ToolkitHard-coded or predictable container-service credentials
CVE-2026-76393Splunk AI ToolkitRace condition during model upload
CVE-2026-76394Splunk AI ToolkitMissing authorization in container and connection REST APIs
CVE-2026-76395Splunk AI ToolkitRCE via deserialization of untrusted model data
CVE-2026-76396Splunk AI ToolkitImproper access control through scheduled searches
CVE-2026-76397Splunk AI ToolkitImproper access control in Experiment History REST API
CVE-2026-76398Splunk AI ToolkitUnauthorized deletion of another user’s experiment history
CVE-2026-76399Splunk AI ToolkitIncorrect permissions on app-provided scheduled searches
CVE-2026-76400Splunk Connect for KafkaDoS through unbounded HTTP Event Collector retry handling
CVE-2026-76401Splunk Connect for KafkaRegular expression denial of service through REST API
CVE-2026-76402Splunk Connect for KafkaSSRF and HTTP Event Collector credential exposure
CVE-2026-76403Splunk Connect for KafkaImproper certificate validation with Kerberos authentication
CVE-2026-76404Splunk MCP Server appCritical RCE via unsafe credential-data deserialization
CVE-2026-76405Splunk On-Call (VictorOps)API key disclosure through cleartext KV Store storage

The advisory additionally patches a high-severity server-side request forgery issue in Cisco Talos Intelligence for Enterprise Security Cloud, tracked as CVE-2026-76389.

A user with the get_talos_enrichment capability could send a crafted request to the Talos enrichment REST endpoint, potentially forcing the Splunk instance to contact an attacker-controlled server and expose tokens. The fixed release is Cisco Talos Intelligence version 1.0.3.

Splunk Connect for Kafka version 2.2.7 fixes four issues, including an 8.2-rated SSRF vulnerability that could expose HTTP Event Collector authentication credentials to an attacker-controlled endpoint.

Other Kafka flaws include unbounded event-delivery retries, regular-expression denial-of-service attacks, and improper certificate validation when Kerberos authentication is used.

Organizations should immediately inventory deployed Splunk apps and add-ons, upgrade affected components, and restrict access to Splunk and Kafka Connect REST APIs.

Where prompt patching is not feasible, Splunk recommends disabling or removing vulnerable apps; Kafka operators should also enforce secure HTTP Event Collector transport and configure finite retry limits.

Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version