CVE-2026-76395Patch(splunk / ai_toolkit)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch splunk ai_toolkit systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk AI Toolkit deserializes sparse matrix data without guarding against embedded pickle content. For more information see Troubleshoot the Splunk Machine Learning Toolkit (https://help.splunk.com/en/splunk-cloud-platform/apply-machine-learning/machine-learning-toolkit-user-guide/5.5.0/troubleshooting-mltk/troubleshoot-the-splunk-machine-learning-toolkit) in the Splunk documentation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ai_toolkit

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-08-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
ai_toolkit

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-21: 1Mentions · 2026-08-28: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-28: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-28: 108-2108-28
Signal classification1 categories
Patch
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • Azubuike Ibe@ai_dev_official
    Patch

    Splunk just patched a real one. Arbitrary code execution through a machine learning model file. CVE-2026-76395, disclosed August 19, hits Splunk AI Toolkit versions below 6.0.0. A user holding the Power role can load a model file with crafted sparse matrix data and trigger arbitrary code execution on the Splunk server. The root cause is unsafe pickle deserialization, a model codec that reconstructs objects from file content without guarding against embedded malicious code. CVSS 8.8. The same batch fixed CVE-2026-76391, a privilege escalation flaw where a low-privileged user could inherit system-level session tokens through Agent Run History and run searches with far more access than they should have. CVSS 8.3. Neither of these needs a compromised MCP server. They live in how the AI Toolkit loads models and manages agent sessions, which is arguably a more direct risk. Observability platforms increasingly ship AI and ML tooling as a core feature, not an add-on. That tooling now sits on the same host as your search infrastructure, your data, and your integrations. Pickle deserialization vulnerabilities are a known, recurring category in ML tooling generally, not unique to Splunk. Any platform that lets users load model files is a candidate for the same class of bug if deserialization isn’t handled with care. Patch to AI Toolkit 6.0.0 or later. Review who actually needs Power-role access. Treat AI-adjacent components inside your observability stack with the same scrutiny you give production services, because a code execution bug in your logging platform is not a low-stakes finding. My name is Azubuike Ibe and I write about the AI features that quietly expand the blast radius of tools we already trust. Patched your Splunk AI Toolkit instances yet? #Cybersecurity #Splunk #AIToolkit #DevSecOps #AppSec

    Post summary

    The post warns that Splunk’s AI Toolkit versions below 6.0.0 are vulnerable to arbitrary code execution via unsafe pickle deserialization (CVE‑2026‑76395) and also mentions fixing CVE‑2026‑76391. It recommends upgrading to AI Toolkit 6.0.0 or newer and reviewing Power‑role access for mitigation.

    0405372
    1.5K followersView on X
  • iototsecnews@iototsecnews
    Patch

    Splunk MCP Server などの 17 件の脆弱性が FIX:Across AI Toolkit と Kafka Apps の欠陥も修正 https://iototsecnews.jp/2026/08/20/splunk-patches-critical-mcp-server-rce-and-16-other-security-flaws-across-ai-toolkit-kafka-apps/ Splunk 各種アプリおよびアドオンに存在する、脆弱性 CVE-2026-76404/CVE-2026-76395/CVE-2026-76402 などの動向と対策を解説する記事です。この件の背景にあるのは、デシリアライズ処理の制御不備やアクセス制御の検証不足です。この不備により、リモートからの任意コード実行/認証クレデンシャルの流出/検索所有権限の改ざんといった影響が生じる恐れがあります。対応策として、指定バージョンへの迅速な更新/管理用 API へのアクセス制限/ロール割り当ての再評価が求められます。 #Across AI Toolkit #CVE202676389 #CVE202676391 #CVE202676394 #CVE202676395 #CVE202676396 #CVE202676397 #CVE202676399 #CVE202676402 #CVE202676403 #CVE202676404 #KafkaApps #MCPServer #Splunk #Vulnerability

    Post summary

    The article reports 17 Splunk-related CVEs, highlights deserialization flaws that could allow remote code execution and credential leakage, and stresses the need for prompt updates and stricter access controls.

    00000174
    511 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsplunkai_toolkit---

Explore more