
Splunk just patched a real one. Arbitrary code execution through a machine learning model file. CVE-2026-76395, disclosed August 19, hits Splunk AI Toolkit versions below 6.0.0. A user holding the Power role can load a model file with crafted sparse matrix data and trigger arbitrary code execution on the Splunk server. The root cause is unsafe pickle deserialization, a model codec that reconstructs objects from file content without guarding against embedded malicious code. CVSS 8.8. The same batch fixed CVE-2026-76391, a privilege escalation flaw where a low-privileged user could inherit system-level session tokens through Agent Run History and run searches with far more access than they should have. CVSS 8.3. Neither of these needs a compromised MCP server. They live in how the AI Toolkit loads models and manages agent sessions, which is arguably a more direct risk. Observability platforms increasingly ship AI and ML tooling as a core feature, not an add-on. That tooling now sits on the same host as your search infrastructure, your data, and your integrations. Pickle deserialization vulnerabilities are a known, recurring category in ML tooling generally, not unique to Splunk. Any platform that lets users load model files is a candidate for the same class of bug if deserialization isn’t handled with care. Patch to AI Toolkit 6.0.0 or later. Review who actually needs Power-role access. Treat AI-adjacent components inside your observability stack with the same scrutiny you give production services, because a code execution bug in your logging platform is not a low-stakes finding. My name is Azubuike Ibe and I write about the AI features that quietly expand the blast radius of tools we already trust. Patched your Splunk AI Toolkit instances yet? #Cybersecurity #Splunk #AIToolkit #DevSecOps #AppSec
Post summary
The post warns that Splunk’s AI Toolkit versions below 6.0.0 are vulnerable to arbitrary code execution via unsafe pickle deserialization (CVE‑2026‑76395) and also mentions fixing CVE‑2026‑76391. It recommends upgrading to AI Toolkit 6.0.0 or newer and reviewing Power‑role access for mitigation.

