Splunk MCP Server app logs session and authorization tokens in clear text (CVE-2026-20205)
In Splunk MCP Server app versions below 1.0.3, session and authorization tokens were recorded in clear text where a user with access to the Splunk `_internal` index or the `mcp_tool_admin` capability could view them. Exploitation requires local access to log files or administrative access to internal indexes, and the issue is addressed in version 1.0.3.
Disclosed 15 April 2026 · Record updated 13 September 2026
Impact
Privileged or local users could read other users' session and authorization tokens in clear text, potentially enabling account or session takeover.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-20205
