What happened
NVD published CVE-2026-76286 (CVSS 5.3) on 2026-10-07: Splunk MCP Server below 1.2.1 forwards the authentication token of the user who runs a custom API tool to the URL configured for that tool. A second user who controls the configured URL can capture the token and impersonate the invoking user on the Splunk platform. Requires mcp_tool_execute capability plus a custom tool owned/configured by another user.
Why it matters
Splunk is deploying agentic/MCP surfaces on the SIEM platform; here the MCP server itself becomes a token-stealing conduit where one user's custom tool definition exfiltrates another user's platform credentials to an arbitrary URL — a concrete agentic-tool credential-disclosure class (tool config as an exfiltration channel) affecting a widely used security data platform.
Attack vector
A user with the mcp_tool_execute capability runs a custom API tool configured by another user; the MCP Server sends the invoking user's Splunk platform authentication token to the URL configured for that tool (an SSRF/credential-disclosure, CWE-918). If another user controls that URL, they capture the token and can then access data and perform actions as the invoking user on the Splunk platform.
Affected systems
Splunk MCP Server versions below 1.2.1 (fixed in 1.2.1; advisory SVD-2026-1004)
Mitigation
Upgrade Splunk MCP Server to 1.2.1 or later (SVD-2026-1004). Review which users can configure custom API tools and which roles hold mcp_tool_execute; restrict custom tool definitions to trusted users. Rotate affected Splunk tokens if a custom tool pointed at an untrusted endpoint.