← Vulnerability feed

Vulnerability record · CVE-2026-76399 · published 19 August 2026

CVE-2026-76399: Splunk ai toolkit incorrect permission assignment vulnerability

Splunk · Ai Toolkit

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.

8.1 CVSS 3.1 High EPSS 0.35% · top 73.9% CWE-732 · Incorrect permission assignment
8.1CVSS 3.1 base score
0.35%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
26 Aug 2026Last modified by NVD

Description

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect system integrity. The vulnerability is possible because Splunk AI Toolkit gives the "power" Splunk role permission to modify scheduled searches that run using the permissions of the search owner.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-76399 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-20266Splunk ai toolkit os command injection vulnerabilityIn Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splun…EPSS 0.63%8.8CVE-2026-76395Splunk ai toolkit deserialization of untrusted data vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a mo…EPSS 0.65%8.3CVE-2026-76391Splunk ai toolkit incorrect authorization vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileg…EPSS 0.47%8.3CVE-2026-76394Splunk ai toolkit missing authorization vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configu…EPSS 0.35%8.1CVE-2026-76397Splunk ai toolkit insecure direct object reference vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, …EPSS 0.35%7.5CVE-2026-76396Splunk ai toolkit improper privilege management vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and de…EPSS 0.32%6.5CVE-2026-20238Splunk ai toolkit incorrect authorization vulnerabilityIn Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that …EPSS 0.32%5.9CVE-2026-76393Splunk ai toolkit race condition vulnerabilityIn Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurren…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2026-76399), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.