← Vulnerability feed

Vulnerability record · CVE-2026-76396 · published 19 August 2026

CVE-2026-76396: Splunk ai toolkit improper privilege management vulnerability

Splunk · Ai Toolkit

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit (https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-ai-toolkit/5.7.3/troubleshooting-the-ai-toolkit/troubleshoot-the-ai-toolkit) in the Splunk documentation.

7.5 CVSS 3.1 High EPSS 0.32% · top 77.2% CWE-269 · Improper privilege management
7.5CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
21 Aug 2026Last modified by NVD

Description

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does not mark the apply search command as risky. For more information see Troubleshoot the AI Toolkit (https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-ai-toolkit/5.7.3/troubleshooting-the-ai-toolkit/troubleshoot-the-ai-toolkit) in the Splunk documentation.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-76396 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-20266Splunk ai toolkit os command injection vulnerabilityIn Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splun…EPSS 0.63%8.8CVE-2026-76395Splunk ai toolkit deserialization of untrusted data vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a mo…EPSS 0.65%8.3CVE-2026-76391Splunk ai toolkit incorrect authorization vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileg…EPSS 0.47%8.3CVE-2026-76394Splunk ai toolkit missing authorization vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configu…EPSS 0.35%8.1CVE-2026-76397Splunk ai toolkit insecure direct object reference vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, …EPSS 0.35%8.1CVE-2026-76399Splunk ai toolkit incorrect permission assignment vulnerabilityIn Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Sea…EPSS 0.35%6.5CVE-2026-20238Splunk ai toolkit incorrect authorization vulnerabilityIn Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that …EPSS 0.32%5.9CVE-2026-76393Splunk ai toolkit race condition vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurren…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2026-76396), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.