Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Splunk MCP Server app logs session and authorization tokens in clear text (CVE-2026-20205)

In Splunk MCP Server app versions below 1.0.3, session and authorization tokens were recorded in clear text where a user with access to the Splunk `_internal` index or the `mcp_tool_admin` capability could view them. Exploitation requires local access to log files or administrative access to internal indexes, and the issue is addressed in version 1.0.3.

Disclosed 15 April 2026 · Record updated 13 September 2026

Impact

Privileged or local users could read other users' session and authorization tokens in clear text, potentially enabling account or session takeover.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-20205