Splunk AI Toolkit privilege escalation and MCP Server command execution
Two vulnerabilities in Splunk products allow unauthorized privilege escalation and arbitrary command execution. CVE-2026-76391 enables non-admin users to run searches with system-level privileges in AI Toolkit below 6.0.0, while CVE-2026-76404 allows admin users to execute arbitrary OS commands in MCP Server app below 1.2.1.
Disclosed 19 August 2026 · Record updated 13 September 2026
Impact
Unauthorized users can escalate privileges to run system-level searches and access other users' data; admin users can execute arbitrary operating system commands.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-76391
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-76404
