
Splunk just patched a real one. Arbitrary code execution through a machine learning model file. CVE-2026-76395, disclosed August 19, hits Splunk AI Toolkit versions below 6.0.0. A user holding the Power role can load a model file with crafted sparse matrix data and trigger arbitrary code execution on the Splunk server. The root cause is unsafe pickle deserialization, a model codec that reconstructs objects from file content without guarding against embedded malicious code. CVSS 8.8. The same batch fixed CVE-2026-76391, a privilege escalation flaw where a low-privileged user could inherit system-level session tokens through Agent Run History and run searches with far more access than they should have. CVSS 8.3. Neither of these needs a compromised MCP server. They live in how the AI Toolkit loads models and manages agent sessions, which is arguably a more direct risk. Observability platforms increasingly ship AI and ML tooling as a core feature, not an add-on. That tooling now sits on the same host as your search infrastructure, your data, and your integrations. Pickle deserialization vulnerabilities are a known, recurring category in ML tooling generally, not unique to Splunk. Any platform that lets users load model files is a candidate for the same class of bug if deserialization isn’t handled with care. Patch to AI Toolkit 6.0.0 or later. Review who actually needs Power-role access. Treat AI-adjacent components inside your observability stack with the same scrutiny you give production services, because a code execution bug in your logging platform is not a low-stakes finding. My name is Azubuike Ibe and I write about the AI features that quietly expand the blast radius of tools we already trust. Patched your Splunk AI Toolkit instances yet? #Cybersecurity #Splunk #AIToolkit #DevSecOps #AppSec
Post summary
Splunk’s AI Toolkit was patched for a CVSS 8.8 arbitrary code execution flaw caused by unsafe pickle deserialization, with the advisory urging users to upgrade to version 6.0.0 or later.
