CVE-2026-76391Patch(splunk / ai_toolkit)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk ai_toolkit systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run History. The improper privilege management is possible because the Agent Run History handler replaces the calling user session key with a system authentication token before it performs search operations. For more information see AI Toolkit Agent Launchpad (https://help.splunk.com/en/splunk-enterprise/apply-machine-learning/use-ai-toolkit/6.0.0/ai-toolkit-connections-containers-and-agents/ai-toolkit-agent-launchpad) in the Splunk documentation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ai_toolkit

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ai_toolkit

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-21: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-08-21: 108-21
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Azubuike Ibe@ai_dev_official
    Patch

    Splunk just patched a real one. Arbitrary code execution through a machine learning model file. CVE-2026-76395, disclosed August 19, hits Splunk AI Toolkit versions below 6.0.0. A user holding the Power role can load a model file with crafted sparse matrix data and trigger arbitrary code execution on the Splunk server. The root cause is unsafe pickle deserialization, a model codec that reconstructs objects from file content without guarding against embedded malicious code. CVSS 8.8. The same batch fixed CVE-2026-76391, a privilege escalation flaw where a low-privileged user could inherit system-level session tokens through Agent Run History and run searches with far more access than they should have. CVSS 8.3. Neither of these needs a compromised MCP server. They live in how the AI Toolkit loads models and manages agent sessions, which is arguably a more direct risk. Observability platforms increasingly ship AI and ML tooling as a core feature, not an add-on. That tooling now sits on the same host as your search infrastructure, your data, and your integrations. Pickle deserialization vulnerabilities are a known, recurring category in ML tooling generally, not unique to Splunk. Any platform that lets users load model files is a candidate for the same class of bug if deserialization isn’t handled with care. Patch to AI Toolkit 6.0.0 or later. Review who actually needs Power-role access. Treat AI-adjacent components inside your observability stack with the same scrutiny you give production services, because a code execution bug in your logging platform is not a low-stakes finding. My name is Azubuike Ibe and I write about the AI features that quietly expand the blast radius of tools we already trust. Patched your Splunk AI Toolkit instances yet? #Cybersecurity #Splunk #AIToolkit #DevSecOps #AppSec

    Post summary

    Splunk’s AI Toolkit was patched for a CVSS 8.8 arbitrary code execution flaw caused by unsafe pickle deserialization, with the advisory urging users to upgrade to version 6.0.0 or later.

    0405372
    1.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunkai_toolkit---

Explore more