Skip to content

$ ls research/

Research

Vulnerability research at the trust boundaries of AI-integrated systems.

Status
Vulnerability class
Publicly disclosedUnsafe Deserialization / Remote Code Execution

CVE-2026-76404: Unsafe Deserialization in Splunk MCP Server

A trust-boundary failure in the Splunk MCP Server app's credential-management path allowed stored data to reach unsafe deserialization, enabling an administrator to execute commands on the underlying operating system.

Product:
Splunk MCP Server app
CVE:
CVE-2026-76404
Publicly disclosedUncontrolled Resource Consumption / Denial of Service

CVE-2026-73635: Request-Locale Cache Exhaustion in Apache Struts

Request-controlled locale values could drive unbounded growth of Apache Struts localized-text caches and exhaust the Java heap when no fixed locale was configured.

Product:
Apache Struts
CVE:
CVE-2026-73635
JVN:
JVN#08517956
Publicly disclosedAccess Bypass

CVE-2026-13236: Tool and Field Authorization in Drupal AI Agents

Drupal AI Agents tools could load content without sufficiently enforcing the required access checks, demonstrating why agent access, tool access, entity access, and field access must be evaluated separately.

Product:
Drupal AI Agents
CVE:
CVE-2026-13236
JVN:
JVN#20592637