Splunk
Splunk AI Toolkit: vulnerabilidades y CVE
Splunk AI Toolkit tiene 12 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses12
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-76399 | Alta (8.1) | 0.35% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search… |
| CVE-2026-76398 | Media (4.3) | 0.25% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer… |
| CVE-2026-76397 | Alta (8.1) | 0.35% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is… |
| CVE-2026-76396 | Alta (7.5) | 0.32% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper… |
| CVE-2026-76395 | Alta (8.8) | 0.65% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of… |
| CVE-2026-76394 | Alta (8.3) | 0.35% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data… |
| CVE-2026-76393 | Media (5.9) | 0.18% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model… |
| CVE-2026-76392 | Media (5.4) | 0.23% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials… |
| CVE-2026-76391 | Alta (8.3) | 0.47% | — | 19 ago 2026 | In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or… |
| CVE-2026-20266 | Crítica (9.1) | 0.63% | — | 17 jun 2026 | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands on the host running the Splunk Enterprise instance. The vulnerability is possible because of an… |
| CVE-2026-20265 | Media (4.3) | 0.22% | — | 17 jun 2026 | In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make outbound requests over HTTP to a server that an attacker… |
| CVE-2026-20238 | Media (6.5) | 0.32% | — | 20 may 2026 | In Splunk AI Toolkit versions below 5.7.3, a low-privileged user that does not hold the 'admin' or 'power' roles could access confidential data that was restricted through `srchFilter` configurations on custom… |